In normal mode you have read&write access to CAL. So I think downgrade can be done with writing some old cert to CAL, then rebooting & flashing old version of fiasco.