Currently, certctl rehash will just keep clobbering .0 rather than incrementing the suffix upon encountering a duplicate. Do this, and do it for blacklisted certs as well.
Future work needs to completely revamp the blacklist to align more with how it's described in PR 246614.
PR: 246614