MinProtocol = TLSv1in an OpenSSL config file pointed to by OPENSSL_CONF. We were doing this because a number of NROs (and eduroam CAT) don't support the newer TLS versions mandated by our operating system, and fail to connect if TLS 1.0 cannot be negotiated. I'm led to believe that there's also a bug in Radiator (widely used) that results in this behaviour.
CipherString = DEFAULT@SECLEVEL=1