Local transparent proxy
From https://wiki.archlinux.org/index.php/User:Grawity/Adding_a_trusted_CA_certificate
Currently Arch Linux uses p11-kit from Fedora, which has more features (e.g. explicit distrusts) than the older scripts from Debian. To import a trust anchor using p11-kit, do: