Many thanks for your answer and recommandation Matt!
So if I understand, and as the Secure Transport API is actually used by CF/NSStreams (BSD sockets), we need to give them up and use Network Framework sockets instead, as described in this thread: https://developer.apple.com/forums/thread/128334 ?