I have not tested this "in-depth", but the code looks good, and the result passes my t_client rig with various OpenSSL and mbedTLS versions.
(I have not actually tested "both server and client have CHACHA-POLY active and using that works" but I trust Antonio there :-) ) Your patch has been applied to the master branch. commit a38a377fd524d0e14a23ed17487ea3e3d3ad3fe7 Author: Arne Schwabe Date: Wed Aug 18 23:33:54 2021 +0200 Include Chacha20-Poly1305 into default --data-ciphers when available Signed-off-by: Arne Schwabe <a...@rfc2549.org> Acked-by: Antonio Quartulli <anto...@openvpn.net> Message-Id: <20210818213354.687736-2-a...@rfc2549.org> URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg22745.html Signed-off-by: Gert Doering <g...@greenie.muc.de> -- kind regards, Gert Doering _______________________________________________ Openvpn-devel mailing list Openvpn-devel@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-devel