KSSL ingress data processing could sometimes end up with corrupted data. This is externalized by SSL alerts sent by KSSL proxy and kstat kssl_internal_errors counter being incremented.
DEBUG kssl kernel module produces e.g. the following warnings in such case:
Oct 8 09:15:05 pickup kssl: WARNING: kssl_handle_any_record: msg MAC mismatch
Oct 8 09:15:05 pickup kssl: WARNING: sending an alert 2 20 from fffffffff3e87b63