> I wasn't aware the EU had such authority to decide how programs on a users private computer must behave.
Why not? They publish directives that result in criminal law in member states all the time.
A directive is published, member states are obligated to turn that into domestic legislation, and yes, ultimately a state can criminalise lots of things if it wants to.
Key word "such". Prescribing which certificates I am obligated to trust is many many steps beyond e.g. banning DRM circumvention (which is itself a step too far IMO).
Why not? They publish directives that result in criminal law in member states all the time.
A directive is published, member states are obligated to turn that into domestic legislation, and yes, ultimately a state can criminalise lots of things if it wants to.