Open
Description
It would seem (according to an email report) that upstream self-signed certificates do not work, this needs to be checked.
Then, we need to figure out whether self-signed or invalid certificates should be allowed by default. I don’t see a security risk from doing that but it might make debugging harder or more confusing because we would bypass those issues.
I’m thinking the best option is to add it behind a flag.