* verify upstream certs & reject unverified * update transport to only harden TLS & rm (http.Transport).Clone