Remove 3DES support by default
3DES due to its 64-bit block size has different security data limits than any other TLS or DTLS ciphersuite in gnutls. Given that TLS and DTLS connections are expected to handle data up to 2^64 or 2^48 correspondingly, the shorter data limits of 3DES break that expectation. As such 3DES should not be present in the default priorities for TLS and DTLS and should be explicitly be enabled for applications that require it.
Such a move would make the versions of gnutls which include it, incompatible with old servers that only support 3DES (windows XP and other similar servers).