no need to check s->server as default_nid is never used for TLS 1.2 client authentication