> Given that NetBSD ships with no CA roots, I never bothered to add the > necessary verification. It would have been more harmful. I disagree that it would have been more harmful, as long as cert verification is skipped when no certificates are present. Using HTTPS with no way to verify certificates is a bad idea. —Benny.