Some governments have PKI with roots that do not meet the requirements to be in
Mozilla's Root CA Program but still generally follow industry practices (and
are trusted by other root CA programs). Many users need to visit sites with
certificates issued by these roots. Currently, they either must manually
install these roots or click through certificate error pages. We may have an
opportunity to improve this experience by detecting sites affected by this and
giving users the option to trust the relevant roots.
This patch extends the telemetry we collect on certificate error pages to
include an indication of whether or not trusting the India CCA roots would
(probably) turn an unknown issuer error into a successful connection.
Differential Revision: https://phabricator.services.mozilla.com/D219116