at least against a given .pem, but preferably against a configurable dir of trusted roots (like /etc/ssl/certs)