PASS: serving cert carries Basic Constraints CA:TRUE (mimics Proton Bridge) === generate himalaya.toml via integration_proton._build_config === GENERATED himalaya.toml === generated config: integration pins imap.tls.cert + smtp.tls.cert === PASS: generated himalaya config pins imap.tls.cert at the Bridge cert PASS: generated himalaya config pins smtp.tls.cert at the Bridge cert === IMAP positive: himalaya trusts the CA:TRUE cert via the integration's pin === PASS: himalaya completed TLS against the CA:TRUE cert (integration pin works) PASS: no CaUsedAsEndEntity / cert error from himalaya when pinned === IMAP negative: strip the integration's pin -> default verifier rejects CA:TRUE === PASS: without the pin himalaya rejects the CA:TRUE cert (the hazard is real) === SMTP positive: himalaya trusts the CA:TRUE cert via the integration's pin === PASS: himalaya trusted the CA:TRUE cert via smtp.tls.cert (no cert error) === SMTP negative: strip the integration's pin -> default verifier rejects CA:TRUE === PASS: without the pin himalaya rejects the CA:TRUE cert over SMTP RESULT: ALL-PASS