Hi Paul--
I think you mean that the signature algorithm uses SHA1, not that it's a
SHA1 fingerprint.
I agree with you that this is bad practice, but it doesn't actually
matter for root certificates. For a root certificate, what matters is
the public key in question, not how it's signed.
That said, it would be nice to have a re-generated root certificate that
uses a modern signing algorithm just to avoid anyone worrying about it
(or some toolkit being overly-strict and deciding to not accept it).
I've cc'ed the upstream maintainer of that CA, Kristian Fiskerstrand, to
see whether he's willing to issue an updated root cert with the same key
material but using a modern signing algorithm.
Thanks for the heads up,