I am a bit wary that someone started adding certificates to the trust store based on this new behavior not realizing that some is using it with a different semantic. Maybe a note ("other software may not do the same") would be appropiate.
I can't find the entry for this in CHANGES, though. PS: sed -i 's/reported to OpenSSL Guido/reported to OpenSSL by Guido/;s/Langley(/Langley (/' CHANGES -- openssl-users mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users