What happens if a byte-identical certificate is placed in metadata twice, once as an explicit use="signing" and once as an explicit use="encryption", as compared to the more traditional use of separate keys or no use element?