With the inclusion of caroot bits, we'll need to also rehash on update as we do in mergemaster/etcupdate.
If certctl's installed on the system, just unconditionally rehash. This isn't an expensive operation, and we can refine it to compare INDEX-{OLD,NEW} later if we really want to.