One final task need be done before I would think it good to submit upstream,
and that is to specify to fail on lack of client certificates only when
specified in an option file. The rest should not change conserver behavior without administrator/user request.