.onion certs can now go the whole chain such that you don't need to rely on non-tor access to do the auth