Fix notification DoS introduced by PR 3490.
PR #3490 added the `--insecure` option to the cURL calls made by alarm-notify.sh to disable TLS certificate validation and make things work without user intervention if cURL can't find the local TLS certificate store. This allows a trivial DoS of notification deliver via channels other than e-mail and IRC by an attacker hijacking the outbound HTTPS connection, scripting the response, and dropping the notification. It also allows trivial disclosure of information about the state of the system (including disclosing what software is running on the system and potentially certain aspects of it's configuration). Here, we change the unconditional use of `--inescure` to be dependent on the value of a variable in health_alarm_notify.conf, and make that variable default to not enabling the option while putting a big warning right next to it about the security implications. Most users should never need to disable TLS certificate validation.