current changes look good. Remaining item is still the ECDSA, I think
Well the upstream patch will take some discussion, I would rather just merge this and file a follow-up ticket so we do not forget to enable testing for the versions of openssl that will support it.
I think it is ok to let the code try and return an error on older versions, there isn't much else we can do except trying to return early, but it is not worth the added special code as it would need to be behind some features etc...
Originally posted by @simo5 in #357 (comment)