PASS: serving cert carries Basic Constraints CA:TRUE (mimics Proton Bridge) === generate himalaya.toml + msmtprc via integration_proton._build_config === GENERATED himalaya.toml + msmtprc === generated config: integration pins backend.encryption.cert + tls_trust_file === PASS: generated himalaya config pins backend.encryption.cert at the Bridge cert PASS: generated msmtprc carries tls_trust_file at the Bridge cert === IMAP positive: himalaya trusts the CA:TRUE cert via the integration's pin === FAIL: himalaya did NOT complete TLS (stub: IMAP_LISTEN 14143) PASS: no CaUsedAsEndEntity / cert error from himalaya when pinned === IMAP negative: strip the integration's pin -> default verifier rejects CA:TRUE === FAIL: expected a TLS rejection without pin, got: Suggestions: - Run with --log-level to enable more verbose logs === SMTP positive: msmtp trusts the CA:TRUE cert via the integration's tls_trust_file === PASS: msmtp trusted the CA:TRUE cert via tls_trust_file (no cert error) === SMTP negative: point trust_file at an unrelated cert -> msmtp must reject === PASS: msmtp rejected the mismatched cert (trust_file is enforced) RESULT: FAILURES