The one difference between the system openssl and a separately compiled one is that the former can use the CA root from the KeyChain (and uses a private API to do that, as noted earlier).

I just stumbled across a utility that can sync the KeyChain to an OpenSSL CA file: <>, and a blog message at <>
