2015-04-14 UTC
# bengo It appears based on other pulls that the main indiecert deployment is just using the host OS's trusted CAs. I suppose I'm proposing to either allow for an explicit whitelist that can be peer-reviewed in the source code, or just for his cURL requests to use the insecure flag, but verify via fingerprint