You also need to trust the root certificates that they don't give key access to the VPN or ISP
https://certificate.transparency.dev/