One more step down the path which started by flagging all self signed certificate as malicious: Now in case of TLS errors, Firefox will *silently* update its trust store (importing things from the OS) and re-attempt the connection, hence allowing all kind of hijacks by antivirus scanners and so... An essential "Enterprise" feature. An again, like DOH, this is enabled by default (activated after first TLS error)!

@pmevzek that setting should only exist in the ESR releases
