The workaround in that thread worked for me as well. (Using NSS Preferences plugin to change maximum TLS version to 1.2.) It seems something is causing issues if TLS 1.3 is permitted, there is some discussion of proposed patches.
I had the same problem, as also discussed in
https://bugs.archlinux.org/task/68357
- Bug#972713: libnss3: Handshake failed (-12251) with ... Kevin Locke
- Bug#972713: libnss3: Handshake failed (-12251) ... Kevin Locke
- Bug#972713: libnss3: Handshake failed (-12251) ... Russ Allbery
- Bug#972713: libnss3: Handshake failed (-12251) ... Adrian Immanuel Kiess
- Bug#972713: libnss3: Handshake failed (-12251) ... Michael Stone

