TLS hardening: verify-peer by default
Earlier this year we shipped verified TLS/HTTPS support in CMSDK, with a network_https test performing a real handshake and encrypted round-trips over loopback using a runtime-generated certificate. That proved the transport worked. It did not, on its own, make it safe by default — and we said at the time that certificate-verification hardening was on…
