-
Notifications
You must be signed in to change notification settings - Fork 5.3k
Closed
Labels
area/tlsenhancementFeature requests. Not bugs or questions.Feature requests. Not bugs or questions.help wantedNeeds help!Needs help!
Description
Title: Support P-384 and P-521 Server ECDSA Certificates
Description:
Update Envoy to support server ECDSA certificates P-384 and P-521. Given that BoringSSL supports these curves, Envoy should allow servers to use certs with those curves to terminate TLS. The expected behavior is for Envoy to take an ECDSA cert and check to make sure it uses one of the three approved curves.
Relevant Links
Older PR for rejecting non P-256 server ECDSA certs: #5224
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
area/tlsenhancementFeature requests. Not bugs or questions.Feature requests. Not bugs or questions.help wantedNeeds help!Needs help!