okhttp BasicCertificateChainCleaner uses the value of CustomCertManager.acceptedIssuers, but we don't return anything.
We should find out what BasicCertificateChainCleaner exactly does and why and whether we should return something in acceptedIssuers.
It may also be useful to implement X509ExtendedTrustManager for Android. Then okhttp would use AndroidCertificateChainCleaner.