Envoy supports both TLS termination in listeners as well as TLS origination
use BoringSSL as the TLS provider.
BoringSSL can be built in a FIPS-compliant mode, it doesn’t support the most recent QUIC APIs.
not enabled unless the validation context specifies one or more trusted authority certificates.
DownstreamTlsContexts support multiple TLS certificates.