Drop the --with-cacert configure option, which does nothing at all. OpenNTPD always loads the root CA file from the path returned by tls_default_ca_cert_file(), i.e., /etc/ssl/cert.pem.