The existing whitelisting functionality does not support the scenario where you do not want to contact notaries for a set of sites, but you also do not want to automatically trust the certs for that site. I can see two ways of addressing this:
1) Add a binary option to the existing "whitelist" indicating whether the user wants to auto-trust those certificates or not.
2) Add a "blacklist" of sites for which the notaries should not be contacted.
I'd go with option 2 as it allows for more options, though I would rather call it an "ignore list" than a blacklist. Blacklist sounds more like DISTRUST those sites.
The existing whitelisting functionality does not support the scenario where you do not want to contact notaries for a set of sites, but you also do not want to automatically trust the certs for that site. I can see two ways of addressing this:
1) Add a binary option to the existing "whitelist" indicating whether the user wants to auto-trust those certificates or not. 2) Add a "blacklist" of sites for which the notaries should not be contacted.