Answers the anchor the client truststore adds: the service Root, read on each call.
the Root's PEM, or an empty string when tls.trustIssuedClientCertificates is off or there is no Root
tls.trustIssuedClientCertificates
Answers the anchor the client truststore adds: the service Root, read on each call.