This is blocked by having the ability to specify values from the X5C certificate in certificate templates -- https://github.com/smallstep/certificates/issues/433.