mode should be tcp in frontend and in backend too, and to check fqdn use this:
tcp-request inspect-delay 5s tcp-request content accept if { req.ssl_sni -m end hub.mydomain } use_backend be_registry_443 if { req.ssl_sni -m end hub.mydomain }