> So if OpenSSL client connects to server that supports PSS but not TLS 1.3, the connection will fail because the client vomits at the server response?
I *think* it will fail cleanly because it gets an ALERT message, but I am not sure. I am no longer involved with OpenSSL, I just did a cursory read of the source. _______________________________________________ Uta mailing list Uta@ietf.org https://www.ietf.org/mailman/listinfo/uta