https://community.qualys.com/blogs/securitylabs/2011/10/31/tls-renegotiation-and-denial-of-service-attacks Secure Client-Initiated Renegotiation can be supressed with require('tls').CLIENT_RENEG_LIMIT = 0; at least for v0.11-v0.12