Loads of SSL handshake failure errors

In the configuration above you have included alpn h2,http/1.1, but it doesn’t seem to be actually enabled on the site you send me.

Can you confirm what is actually the case?

I don’t see anything wrong with the configuration, it does requires SNI, so Android 2 and Internet Explorer on Windows XP will not work. Also Java 6 doesn’t work because of the DH-group being 2048 bit (but this doesn’t affect customers accessing with browsers). And if h2 is enabled, Chrome 49 on Windows XP also will not work if you have long URIs or large cookies.

You’ll have to understand what the actual OS/browser is that fails, and that you expect to work.