While I disagreed with you on some PKI-related topics, I fully agree with you on that specific one.
GnuTLS is bad.

(back reading that new triple handshake TLS attack)

Perhaps folks will take us more seriously the next time we say "don't use GnuTLS" ... http://www.openldap.org/lists/openldap-devel/200802/msg00072.html