crypto/tls.Config.RootCAs
states
// RootCAs defines the set of root certificate authorities
// that clients use when verifying server certificates.
// If RootCAs is nil, TLS uses the host's root CA set.
On Linux, where are "the host's root CA set" picked up from? I need to know this to be able to globally add another root CA to trust.