Fixed by the openssl 3.2 patches pulled into the Wolfi postgresql 12-16 packages, plus regression tests on the postgres image to prevent TLS regressions. The reporter verified the client connects over TLS again. Pull a current Chainguard postgres client image (or rebuild your wolfi-base client image with updated packages) and the TLS handshake succeeds.
Source: https://github.com/chainguard-images/images/issues/1898
Source: https://github.com/chainguard-images/images/issues/1898