Taking a specific point from #1123, we should encourage adoption of security enhancements with the desired tradeoff between compatibility and security. This should be done through some combination of sane defaults and a good UI that groups these security enhancements together and/or succinctly explains why and when these security enhancements should be taken. If security enhancements are grouped together, they should still be able to be chosen individually by experienced sysadmins.
There's a lot in flux on Certbot right now related to this and even if we do this, we won't get to it for a while so I'm closing the issue for now.