Skip to content

Revisit and modernize ciphersuite specification mechanism ("cipher string") #5050

@kaduk

Description

@kaduk

There is pent-up demand for a more flexible solution than the current cipherstring setup, most notably for equal-preference grouping (#541) and a more general solution than SSL_OP_PRIORITIZE_CHACHA (#4436).

Rather than focusing on a specific mechanism ("bracketed equal-preference" or "prioritize chacha"), let's try to step back and think about what is actually needed (including whether @STRENGTH still makes sense, since that is not easily compatible with the bracketed equal-preference scheme) and how we can fill that need.

However, this is likely to be a big revamp and might be backwards incompatible, so let's mark this as for 1.2.0/post-1.1.1 to start.

Metadata

Metadata

Assignees

No one assigned

    Labels

    inactiveThis label should not be applied to open issues anymore.triaged: featureThe issue/pr requests/adds a feature

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions