>>  The other is making all of 9.2.2 (and maybe 9.2.1) specific to TLS 1.2; i.e., to let TLS 1.3 and beyond control their own destiny.
> That sounds like a good idea in any case (independently of whether it
> addresses Greg's concerns wrt TLS 1.2).

Given that TLS have already agreed to make the same restrictions
(aside from mandatory to implement cipher suite) that 9.2.2 makes, I
see only upside to this.  The only restriction that seems like it
could be special is the SNI one, for which I will create a special

