The attached rebase brings a few more tests by Jacob for ensuring that a) CA's
entirely replace when a host config is matched; b) that CRL's work as intended
for certificates configured in pg_hosts.conf; and c) ssl_sni and TLS init
aren't configured at the same time.
This concludes all TODOs in the code, unless there are review objections I plan
to go ahead with this version within a few days.
--
Daniel Gustafsson