Do other softwares support specifying a CA bundle per domain or cert pinning?
Should FIPS specify a more limited CA cert bundle and/or cert pinning that users manage?
When the user approves a self-signed cert in the browser, isn't that cert pinning but without PKI risks and assurances?
What about CRL and OCSP; over what channel do they retrieve the cert revocation list; and can CT Certificate Transparency on a blockchain to the browser do better at [pinned] cert revocation?