Don't allow a CCS when expecting a CertificateVerify