* I shouldn't have to care where the certificates are stored. Just load the os default ones without asking me.
* I shouldn't have to know what a pem is, and I shouldn't have to open() one.
* I don't want a PolicyBuilder. Just give me the normal policy.
* I shouldn't have to construct some verifier object specific to a given dns. I don't want to verify a billion certificates for one domain, just one.
* I shouldn't have to know what an untrusted intermediary is.
Here's what I think it should look like
verifier = Verifier() # constructs a verifier with sensible defaults, overrides are possible though
verifier.verify(chain, "cryptography.io")