At present the check for which transport to use references a configuration option that has been removed. Update check to test for current configuration option plus add a check for presence of `tls-certificates` relation. Also remove insecure option and add verify option to allow control of verification including providing own CA certificate bundle. Reference for verify option: https://docs.openstack.org/keystoneauth/latest/api/keystoneauth1.html#keystoneauth1.session.Session