Depends on pypa/pip#11082
We should ensure we don't break any of pip's users trying to use our experimental feature flag --use-feature=truststore, at least for a basic installation from PyPI. It's tougher for us to simulate installing from corporate proxies/package indices but maybe we can do something with mkcert and warehouse?