* d/copyright: use ./ prefix to upstream filenames, because orig.tar.gz
     is build with a ./ prefix.
   * Compile --with-mbedtls to allow https-inspection.
+  * Adapt TLS/SSL settings to Debian FHS.
+  * Generate dirs with correct permissions for https-inspection.
 
- -- Roland Rosenfeld <roland@debian.org>  Sat, 04 Apr 2020 14:46:51 +0200
+ -- Roland Rosenfeld <roland@debian.org>  Fri, 05 Jun 2020 18:13:53 +0200
 
 privoxy (3.0.28-3) unstable; urgency=medium
 
 
 From: Roland Rosenfeld <roland@debian.org>
-Date: Sat, 11 Feb 2006 21:27:14 +0100
+Date: Fri, 05 Jun 2020 15:51:09 +0200
 Subject: Several Debian specific changes to config file
 
 --- a/config
  #
  #  2.5. actionsfile
  #  =================
+@@ -2474,7 +2474,7 @@ socket-timeout 300
+ #
+ #      ca-directory /usr/local/etc/privoxy/CA
+ #
+-#ca-directory /usr/local/etc/privoxy/CA
++#ca-directory /etc/privoxy/CA
+ #
+ #  7.2. ca-cert-file
+ #  ==================
+@@ -2615,7 +2615,7 @@ socket-timeout 300
+ #
+ #      certificate-directory /usr/local/var/privoxy/certs
+ #
+-#certificate-directory /usr/local/var/privoxy/certs
++#certificate-directory /var/lib/privoxy/certs
+ #
+ #  7.6. trusted-cas-file
+ #  ======================
+@@ -2648,7 +2648,7 @@ socket-timeout 300
+ #
+ #      trusted-cas-file trusted_cas_file.pem
+ #
+-#trusted-cas-file trustedCAs.pem
++#trusted-cas-file /etc/ssl/certs/ca-certificates.crt
+ #
+ #  8. WINDOWS GUI OPTIONS
+ #  =======================
 
        chown privoxy $CONFDIR/user.action $CONFDIR/trust
        [ -f $CONFDIR/match-all.action ] \
            && chown privoxy $CONFDIR/match-all.action
+       chown privoxy:adm /var/lib/privoxy/certs
+       chmod 700 /var/lib/privoxy/certs
 
        db_get privoxy/listen-address || true
        perl -le '