for mono my suspicion is it has a similar certificate chain validation bug in its embedded boringssl than earlier openssl, e.g. cannot terminate chain validation if they find the first valid certificate.