There's some work in Leste repo on updating maemo-security-certman to use openssl 1.1.0. Not sure if that will help out as well in the long run to keep components and certificates up to date. Some Leste components like that could be backported to Fremantle to aid in testing.
ok I confirmed that yes microb-engine is using its own crypto code (NSS) and not openssl so we need to look into that. It does however tap into the maemosec stuff for its root certificates (makes sense, that way there is only one set of root certificates for the entire device)