It was always intended that PKCS1 is not used, now the standard actually says this.
It may be desireable for FAPI to go further than this, but everyone is agreed that we want at least this.
As per suggestion from Brian Campbell on the issue.
The way I've added a subsection for encryption is perhaps a little odd. It's an attempt to preserve numbering whilst also not making it awkward to add further JWS restrictions in the future.