[pfx] Re: Brainpool support

2025-01-22 Thread Damian via Postfix-users
OpenSSL supports or does not support curves, Postfix just uses OpenSSL, but the *default* list of curves passed to OpenSSL: tls_eecdh_auto_curves = X25519 X448 prime256v1 secp384r1 secp521r1 tls_ffdhe_auto_groups = ffdhe2048 ffdhe3072 is deliberately pruned to just the mainstream optio

[pfx] Re: Brainpool support

2025-01-21 Thread Viktor Dukhovni via Postfix-users
On Tue, Jan 21, 2025 at 02:32:05PM +0100, Damian via Postfix-users wrote: > Does Postfix support Brainpool curves? OpenSSL supports or does not support curves, Postfix just uses OpenSSL, but the *default* list of curves passed to OpenSSL: tls_eecdh_auto_curves = X25519 X448 prime256v1 secp38