There's a difference between saying that a TLS 1.3 client MUST NOT advertise client hello with TLS_RSA_* ciphersuites listed, and just having TLS 1.3 not supporting RSA key exchange.
1197627212858460https://smlouvy.gov.cz/smlouva/128584602020-06-03T10:52:20 02:00uccchjmSpráva železnic, státní organizace70994234Dlážděná 1003/7, 11000 Praha 1, CZmaafhaeOLTIS Group a.s.26847281Dr.