Include the ability to perform certificate checking/trusting.
This should allow specific public keys to be trusted along with trusting all certificates signed by Root/Intermediate CAs.
It should be enough to trust an intermediate CA without verifying the entire chain.