In general, take a look at upstream SSL stats so it's more clear when there are failures. Also potentially add warning to docs around what an empty ssl_context does.