Server only uses curves that are supported by both the client and the server. If no common groups are found, the connection will fail in TLS 1.2 and below. In TLS 1.3, HRR may still be used to resolve the group mismatch.
- fix incorrect alert type being sent - error out when we receive a CCS before a CH - error out when we receive an encrypted CCS