KEYS: verify a certificate is signed by a 'trusted' key