The prototype of tls_lookup_cfg() can be changed if needed, that's not a problem.
The solution with xavp is ok and available now, the one with new match attribute may be an alternative the config simpler.
Anyhow, I am closing this one, given there is a solution. If anyone considers to implement the match config option, then a new pr should be opened.