First, trying to figure out the whole 127.0.0.1 certificate thing. 127.0.0.1 is a loop that remains on the local machine, so where the hell would it even get a certificate?
Second, and I am thinking I might be getting closer here, in that ProtonMail Bridge is secure from the local machine out into the great wide world, I shouldn't really need a secure connection from KMail to 127.0.0.1, which is the bridge. I wonder if I'm inserting something that needn't/oughtn't be there.
Does any of this make sense?