bneradt opened a new pull request, #12628:
URL: https://github.com/apache/trafficserver/pull/12628

   Building on PR #11844 which added TLS group metrics, this change uses 
SSL_CTX_get0_implemented_groups() to dynamically discover all supported TLS 
groups at initialization, including KEMs (Key Encapsulation Mechanisms) like 
X25519MLKEM768 and SecP256r1MLKEM768 that don't have standard NIDs defined in 
older OpenSSL versions. This fixes issue #12622 where KEM groups were being 
reported as OTHER instead of their actual group names. The implementation adds 
a new conditional compilation path that uses string-based group maps (similar 
to BoringSSL) when SSL_CTX_get0_implemented_groups is available, falling back 
to the NID-based approach for older OpenSSL 3.x versions.
   
   Fixes: #12622


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to