I am a bit wary that someone started adding certificates to the trust store based on this new behavior not realizing that some is using it with a different semantic. Maybe a note ("other software may not do the same") would be appropiate. I can't find the entry for this in CHANGES, though. PS:?sed -i 's/reported to OpenSSL Guido/reported to OpenSSL by Guido/;s/Langley(/Langley (/' CHANGES