One must be able to use the deprecated SSL versions. Thing to consider: switch to old SSL automatically if failed?