So they're using Google's BoringSSL, which according to Google itself isn't intended for general use:
> Although BoringSSL is an open source project, it is not intended for general use, as OpenSSL is. We don't recommend that third parties depend upon it. Doing so is likely to be frustrating because there are no guarantees of API or ABI stability.
Jesus Christ that is well overdue - I know mono isn't exactly like Microsoft's projects but why Microsoft never treats security - especially cyphers and protocols with any sense of urgency baffles me.
I wanted to post "Patches welcome!", but then I remembered, wasn't mono backed by commercial company and then bought by Microsoft? It's a shame that they are lagging behind in security critical areas.