`hermes` (hermes_cli.main) and the TUI gateway call install_truststore()
at startup; the two other console scripts did not, so bare requests /
urllib calls made before the first model client (which installs it
lazily) verified against OpenSSL's compiled-in paths instead of the OS
store — a corporate root would fail there and nowhere else.