Second PR in the staged plan from [#33370](https://github.com/fleetdm/fleet/issues/33370#issuecomment-4394807680). Per [@getvictor's confirmation](https://github.com/fleetdm/fleet/issues/33370#issuecomment-4421816049), takes the package-level var approach so tests can swap `initFatal` without terminating the test binary. The new `TestGetTLSConfigInvalidProfile` covers `getTLSConfig`'s default case (previously unreachable in tests because it calls `initFatal`) **Related issue:** Part of #33370. # Checklist for submitter If some of the following don't apply, delete the relevant line. ## Testing - [x] Added/updated automated tests ## Database migrations _N/A — no database migrations in this PR._ ## New Fleet configuration settings _N/A — no new configuration settings._ ## fleetd/orbit/Fleet Desktop _N/A — no agent code changes._ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Improved test coverage for TLS configuration error handling. [](https://app.coderabbit.ai/change-stack/fleetdm/fleet/pull/45343) <!-- end of auto-generated comment: release notes by coderabbit.ai -->