--enable-policy-checks
--disable-policy-checks
--enable-crl-checks
--disable-crl-checks
--enable-trusted-cert-crl-check
--disable-trusted-cert-crl-check
--force-crl-refresh
--enable-ocsp
--disable-ocsp
--auto-issuer-key-retrieve
--validation-model
name--ignore-cert-extension
oid2.5.29.3
. This option may used more than once. Critical
flagged certificate extensions matching one of the OIDs in the list
are treated as if they are actually handled and thus the certificate
won't be rejected due to an unknown critical extension. Use this
option with care because extensions are usually flagged as critical
for a reason.