|
@marcan42 | |||||
|
Worth noting that RFC5480 disallows custom ECC curves for PKIX, and of course they are also verboten in the WebPKI. But both crypt32 and OpenSSL seem to support it.
|
||||||
|
||||||
|
Salearlyman
@learlyman
|
17. sij |
|
OpenSSL seems to have been aware of the problem at some point? github.com/openssl/openss…
|
||
|
|
||
|
Hector Martin
@marcan42
|
17. sij |
|
Ah, I checked 1.0. Good to know they disabled it.
|
||
|
|
||
|
roothorick
@roothorick
|
17. sij |
|
OpenSSL just kinda supports everything, regardless of whether actually using a thing is a good idea, doesn't it?
|
||
|
|
||
|
Elichai Turkel
@Elichai2
|
18. sij |
|
This is one of the reason I want to implement a minimal TLS library. Trying to support the least weird things while still supporting ~80%+ of the web.
I hope I'll find the time to work on that at some point
|
||
|
|
||