We should support - a known_hosts of registered hosts (what we have right now) - a known_hosts with the CAs used for all currently issued certs (today, we only support one, so just that) - or both. Sharkey-client should grab both by default.