-
Notifications
You must be signed in to change notification settings - Fork 67
Open
Description
None of the configurations enable post-quantum key agreement. Worse, many disable post-quantum key agreement, which is enabled by default with OpenSSL 3.5.0+ and BoringSSL when no curves are configured.
The solution is not that simple. Adding X25519MLKEM768 as curve will break software that hasn't been upgraded to support it yet. Might be best not to set any curves at all and lean on the default of recent TLS libraries.
Metadata
Metadata
Assignees
Labels
No labels