Also, you might consider configuring your server to only support cipher suites that will be supported by TLS 1.3 [0][1] and let old clients get errors. If you need security, don't use the obsolete stuff the experts don't trust anymore.
0 - https://tlswg.github.io/tls13-spec/#rfc.section.1.2
1 - This means use only (ECDHE|DHE)-(RSA|ECDSA)-AES128-GCM-SHA256 and (ECDHE|DHE)-(RSA|ECDSA)-AES256-GCM-SHA384. No key exchanges that don't provide forward secrecy, no RC4, no CBC mode, no MD5, no SHA1.