The system “trust store” should contain the CA certificates in the formats used by OpenSSL and p11-kit. These should cover pretty much all software (except some stubborn one like Java applications):
I’m not sure why it says that: I’ve been using Privoxy built with MbedTLS doing TLS validation for more than an year, so I’m pretty sure MbedTLS can read those certificates.