Without deploying a computer configuration profile, I found that I was
able to toggle "Always Trust" at the parent level on an imported CA
certificate by using all policy constraint options in the command line
e.g. security add-trusted-cert -d -r tru...