1. Which ROOT CA storage does pidgin use to authenticate a server side SSL

2. How can I configure pidgin to use one (and just one; exclusive) ROOT CA
storage (or single certificate) and ignore all other system-wide root certs
without having to recompile the source?

3. How can I harden pidgin to fail connecting to the jabber server if SSL
trust can not be established? I do not want to see any warning that the SSL
cert can not be authenticated or the user being asked if he trusts the
certificate manually.

