Skip to content

Conversation

johubertj
Copy link
Contributor

@johubertj johubertj commented Jun 19, 2025

Release Summary

Resolved issues:

Partially addresses #5152

Description of changes:

Added new security policy: cnsa_1, which is an alias for the existing rfc9151 policy defined in RFC 9151.

Why these changes are being made:

Based on Alex Weibel's (POC) email response on why we should add an alias

We should standardize the s2n TLS Policies on CNSA version names (instead of RFC number names).

Testing:

Existing unit tests for rfc9151 implicitly validate cnsa_1 behavior.

@github-actions github-actions bot added the s2n-core team label Jun 19, 2025
@johubertj johubertj changed the title add cnsa 1 alias feat: add cnsa_1 TLS security policies Jun 19, 2025
@johubertj johubertj requested review from goatgoose and jmayclin June 19, 2025 23:23
@jmayclin
Copy link
Contributor

Can you add a "why" section to this PR? I don't understand the benefit of another alias.

@johubertj johubertj marked this pull request as ready for review June 20, 2025 16:38
@johubertj johubertj requested review from lrstewart and removed request for jmayclin June 23, 2025 21:02
Copy link

This PR has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants