Re: [Openvpn-devel] Should we use mbedTLS certificate profiles?

2017-02-27 Thread David Sommerseth
On 27/02/17 23:06, James Yonan wrote: > On 25/02/2017 08:40, Steffan Karger wrote: [...snip...] >> I'd say so. Something like: >> >> legacy: RSA 1024+, SHA1+, all curves >> default: RSA 2048+, SHA2+, all curves >> suiteb: no RSA, SHA256/SHA384, P-256/P-384 >> >> As long as we kick anything that's

Re: [Openvpn-devel] Should we use mbedTLS certificate profiles?

2017-02-27 Thread James Yonan
On 27/02/2017 18:18, David Sommerseth wrote: > On 27/02/17 23:06, James Yonan wrote: >> On 25/02/2017 08:40, Steffan Karger wrote: > [...snip...] >>> I'd say so. Something like: >>> >>> legacy: RSA 1024+, SHA1+, all curves >>> default: RSA 2048+, SHA2+, all curves >>> suiteb: no RSA,

Re: [Openvpn-devel] Should we use mbedTLS certificate profiles?

2017-02-27 Thread James Yonan
On 25/02/2017 08:40, Steffan Karger wrote: > On 25-02-17 07:04, James Yonan wrote: >> On 24/02/2017 16:10, Steffan Karger wrote: >>> On 24-02-17 22:28, James Yonan wrote: On 24/02/2017 02:40, Steffan Karger wrote: > On 23-02-17 22:41, James Yonan wrote: >> On 23/02/2017 01:22,