Any Plans to Support JARM fingerprints with Suricata

My understanding of JARM is that it requires active scanning (sending of TLS client hello packages) to generate the hash. That means it cannot be generated from an IDS/IPS that is just listening in on the connection.

https://engineering.salesforce.com/easily-identify-malicious-servers-on-the-internet-with-jarm-e095edac525a