Validate it yourself with hashing and PKI. Yes, it needs bootstrapping, just like centralized HTTPS needs bootstrapping.

Wow, thanks!

Also if people need more food for (decentralized) thought:

https://datatracker.ietf.org/doc/html/rfc2289