+
+- Important: The file proxy-dh.pem is now required. tlsproxy-setup creates it,
+ but running it will overwrite the existing proxy-*.pem files (which will
+ invalidate all certificate-*-proxy.pem files). To create only proxy-dh.pem
+ use:
+
+ certtool --generate-dh-params --sec-param high --outfile proxy-dh.pem
+
+- Use "SECURE" as GnuTLS priority string which disallows insecure algorithms.