Tested on sparc64 & hppa, and went into an amd64 bulk build. Node that builtins/certdata.c patch goes to the attic since it's autogenerated at build time from builtins/certdata.txt (which we patch too for CACert roots) since bug #683266. There might be a chemspill for a TURKTRUST CA distrust soon (bug #825022, sg-only) but let's get this in now.