On 5/21/19 4:26 PM, Christoph wrote:
Can you confirm that this is limited to the DoH endpoint and does not
affect DoT?

Yes.  gnutls just behaves nice by default, apparently.  In any case it's best to test, e.g.:

openssl s_client -showcerts -connect odvr.nic.cz:853