User should validate the server certificate, not the CA certificate