On Sun, 19 Apr 2026 03:21:23 +1000
Viktor Dukhovni via Postfix-users <[email protected]> wrote:

>     * With RSA certificates, the key sizes is 2048 or 3072 bits
> 
>     * With ECDSA certificates use a P256 key.
> 
>     * Accept both AES128 and AES256 ciphers, and if posisble accept
>       CBC ciphers.

OK, let's take ECDSA for example, if the P-256 is the baseline
supported by most software, does it make sense having multiple
additional certificates: P-384 and P-521, in case a remote SMTP
software policy allows only these curves? Or is there no practical
advantage at this time?

PS. If I'm not mistaken, this is not an issue for RSA certificates,
since all key sizes are universally supported because RSA uses the same
algorithm.
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to