That's a pretty interesting approach. Might even work!
I wonder if something simple (and stupid) like an LD_PRELOAD with an alternative fixed SSLVerifySignedServerKeyExchange would work. Won't work if the code ends up getting inlined.
Guess not, looks like SSLVerifySignedServerKeyExchange is static.