leafCanSignCertificates

Issues the attested leaf as a CA that may sign certificates. Real attested keys never can; this exists to build chain-extension attack vectors, where a leaf signs a certificate of its own.