TLS scan configuration
Advanced things like "skip", "yes, we want the self-signed cert here", and the ability to ignore specific kinds of problems (particular headers, etc).
Good header list to consider in default config:
Access-Control-Allow-OriginCache-ControlContent-Security-PolicyExpiresHTTP Strict-Transport-SecuritySet-CookieX-Content-Type-OptionsX-Frame-Options (Frame-Options)X-XSS-Protection