- include LetsEncrypt's ISRG Root X1 root as an alternate to try if the platform roots fail
- if
tailscale cert
fails because it needs to be run as root, say so. - avoid looping packets in tstun, believed to fix #1526
- allows SOCKS5 proxy for
--tun=userspace-networking
to dial the HTTPS domain name of the Tailnet - ensure state directory is set to perm 0700.
- ignore ipsec link monitor events for iOS, avoid waking the system