It seems S/MIME Certificates whose Root -CA was set explicitly to "untrusted" are shown as "trusted" in Okular.
Not certified OpenPGP certificates are shown as "trusted", too.
The screenshot shows an S/MIME certificate where the root CA has no trust:
Obviously, the text has to be "not trusted". Same for OpenPGP certificates which are not certified by oneself or another trusted key.
I believe we should also highlight this, as this is very important information and it is hidden in a dropdown view.
