Update where stboot reads trusted TLS signing roots
What needs to be done is specified in https://git.glasklar.is/system-transparency/project/documentation/-/blob/main/proposals/2023-12-05-clean-up-ca-selection.md
What needs to be done is specified in https://git.glasklar.is/system-transparency/project/documentation/-/blob/main/proposals/2023-12-05-clean-up-ca-selection.md