It sets `crl_check_all` as an argument for openssl. Does this end up checking _every_ cert in the chain? Needs testing.