The Microsoft Trust list is signed by Microsoft CAs, we should verify this TL's signature like we do with the EUTL - https://github.com/PeculiarVentures/PKI.js/tree/master/examples/CMS%20Signed%20complex%20example