We've discussed adding hardened defaults to OpenSSL (bug 510798, bug 812794) and GnuTLS (bug 880119) in the past. It turns out Fedora has a great way of handling this *systemwide* with various plugins to generate appropriate configs. This is great for us as a distribution but it's also great for users to easily customise and be sure the new settings are being respected. I think we may want to try it out (https://gitlab.com/redhat-crypto/fedora-crypto-policies), probably with a fork which we rebase regularly to allow us to introduce config divergences easily (even if we have none at first). Note that this gives us way more coverage over things like OpenSSH too!