from tls docs i got the impression that tls config file is currently a
single file.
because peers come and go, it would be nice if config entries could be
read also from a config.d directory when tls.reload is called.
may be too late for 3.1?
-- juha