Am 19.10.21 um 17:47 schrieb Gert Doering: > Acked-by: Gert Doering <[email protected]> > > Now this one is straightforward, even I can ACK it :-) - this change is > good as it will avoid compile mishaps, and since we control what SSL > build we want to use on Windows, we can enforce "always EC!". Not sure > about other platforms (maybe the Software Museum has OpenSSL versions > compiled without EC...).
The software museum wants to support FIPS and FIPS mandates Suite B curves. I would more think that embedded system that stripped their OpenSSL to the mimimum like that one that removed DH/DHCE support a few years ago are problematic. Arne _______________________________________________ Openvpn-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/openvpn-devel
