AFAICT, the tool is broken WRT renegotiation detection.
~% openssl s_client -connect 69.171.228.13:443 2>/dev/null < /dev/null | grep Reneg
Secure Renegotiation IS NOT supported
~% openssl s_client -connect 69.171.228.13:443 2>/dev/null < /dev/null | grep Reneg
Secure Renegotiation IS NOT supported
We tracked down a bug in config autogeneration, and are going to add paranoia to monitor for it in the future.