openconnect: when serverhash or cafile are present, set --no-system-trust