When compiled against a static version of openssl that does not support SHA-1 signatures at all we should not offer any SHA-1 signature mechanism.
When dynamically linking against a version of openssl that does not support SHA-1 signatures, similarly, we should also dynamically check that and not offer the mechanisms ...