Looks like FFDHE is broken in combination with TLSv1.3 in OpenJDK (https://bugs.openjdk.org/browse/JDK-8377159), causing handshake failures for approximately 0.4% of all TLS connections. Fun to debug.
Which shouldn't be an issue since nobody really uses FFDHE because Elliptic Curves are a lot more efficient.
*F5 enters the room* https://my.f5.com/manage/s/article/K000158948