The phone allow an initial connection to an HTTPS file server without validating the certificate chain as long as the server certificate name is validated. Then the phone will download TRUSTCERTS from the HTTPS server which should include a root CA for the HTTPS server certificate. So when the phone is rebooted it will have the proper TRUSTCERTS to fully validate the HTTPS connection.