The way forward will probably be to switch to ECDSA anyway, just like Cloudflare "Universal SSL".
I'll also amend the openssl / certreq commands CertSimple generate to provide an ECC option.
1 - https://tools.ietf.org/html/draft-irtf-cfrg-curves-07
2 - https://www.ietf.org/mail-archive/web/cfrg/current/msg07291....