After all, the root certificate is part of the local trust store (/etc/ssl/ca-bundle.pem), and nginx knows it (ssl_trusted_certificate points to it). Posted at Nginx Forum: http://forum.nginx.org/read.php?2,261716,261785#msg-261785