I think for AWS, this relates to
https://www.amazontrust.com/repository/
https://aws.amazon.com/blogs/security/how-to-prepare-for-aws-move-to-its-own-certificate-authority/
what's the equivalent for verifying certificates used on GCP storage URLs, e.g.
https://storage.googleapis.com/storage_path_name
in cases where the client machine is not trusting the Google server hostname in the giving storage URL. I couldn't find anything online about this so far.