cryptography >= 45.0.0 has support for custom certificate chain verification, it would be useful to support checking EK certificates