pub const CERT_TRUST_PUB_ALLOW_TRUST_MASK: u32 = 3u32;