Fix wording of ChangeLog and 3DES_REMOVE docs
diff --git a/ChangeLog b/ChangeLog
index abd12d5..ee50013 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -8,7 +8,12 @@
at the cost of additional lifetime constraints on the input
buffer, but at the benefit of reduced RAM consumption.
* Add MBEDTLS_REMOVE_3DES_CIPHERSUITES to allow removing 3DES ciphersuites
- from the default list (inactive by default).
+ from the default list (enabled by default). See
+ https://sweet32.info/SWEET32_CCS16.pdf.
+
+API Changes
+ * Add a new X.509 API call `mbedtls_x509_parse_der_nocopy()`.
+ See the Features section for more information.
Bugfix
* Fix a compilation issue with mbedtls_ecp_restart_ctx not being defined
@@ -53,10 +58,6 @@
* Ensure that ssl-opt.h can be run in OS X. #2029
* Ciphersuites based on 3DES now have the lowest priority by default.
-API Changes
- * Add a new X.509 API call `mbedtls_x509_parse_der_nocopy()`.
- See the Features section for more information.
-
= mbed TLS 2.16.0 branch released 2018-12-21
Features