I am in support of the following options (most preferred to least): a) utilize the os' certificate trust store; b) ship Firefox PEM bundle and add an additional flag to utilize it (i.e., here is the path, trust certain signed by these authorities). However I do like and would prefer the current flags continue to act like certificate pins, regardless of what other CA's I trust