> A quick hack fix on the command line is to use the option
> "-ignore_critical".

AFAIK, if the qc is present you could enhance the string
"Verification successful" to
"Verification successful with a signing certificate issued to be legally

.... although to really make sense, openssl would have to have a root
store of CAs accredited to set that flag...
