case:
- The client offers a subset of supported groups
- The server chooses a different algorithm than the clients preference
- After the hello retry requests client hello, the server fails
@nhorman Suspects that the issue might be, that the protection key is recalculated on the second client hello. (see #1289 (comment))