The default version (TLS 1.2) is no longer overridden with TLS 1.3 so the server must explicitly set it. Fixes: ("crypto/tls: allow client to pick TLS 1.3, do not enable it by default.")