trusted root certificates, what should be there by default from apple
Following a recent number of incidents with my machine Ive discovered that within my keychain there are over 160 trusted roots often with three for each body, an unqilified, a rsa and a ca g3 version + many more that i personally dont trust. I understand these can be maintained by the user following install of the os but my ability seems to be locked preventing me removing them. Wanted to know if anyone knew how to enable edit access, what the official list should be as im sure its not this large given there are only 13 root identies so at maximum this list should contain 13 certificates to start with. Similarly how do edit/check the certificates that exist right before install of the os from recovery mode to ensure i have a correctly signed copy. My goal is to ensure the version im installing is the apple worldwide release signed by the apple root server from recovery mode. Thanks
MacBook Pro 16″, 13.2