If a certificate uses SHA1, Apple (or any other vendor) can't help but use that for verification…
This is verifying certificates for HTTPS connections - not creating them. If they removed the SHA1 verification, you can no longer visit hundreds of millions of sites that haven't updated their certificates yet.
It's the people still using certificates with SHA1 hashes that need to upgrade.