Disallow DSA/SHA1/etc. for pure TLS 1.3 ClientHellos