Skip to content

Support P-384 and P-521 Server ECDSA Certificates #10855

Closed
@JoelHenn

Description

@JoelHenn

Title: Support P-384 and P-521 Server ECDSA Certificates

Description:
Update Envoy to support server ECDSA certificates P-384 and P-521. Given that BoringSSL supports these curves, Envoy should allow servers to use certs with those curves to terminate TLS. The expected behavior is for Envoy to take an ECDSA cert and check to make sure it uses one of the three approved curves.

Relevant Links
Older PR for rejecting non P-256 server ECDSA certs: #5224

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions