net: add tests against badssl.com These provide bad X.509 certificates, which we should refuse to connect to by default.