Skip to content

Remove static ECDH cipher suites #9201

@gilles-peskine-arm

Description

@gilles-peskine-arm

Static ECDH is officially deprecated by RFC 9325. It does not exist in TLS 1.3. OpenSSL stopped supporting static (EC)DH in its 1.1.0 release in 2016.

Does Mbed TLS 4 still need to support static ECDH?

(Related: #7679 — if we keep them, they might be disabled by default.)

Mailing list thread: https://lists.trustedfirmware.org/archives/list/mbed-tls@lists.trustedfirmware.org/thread/AVTTVTS654DD45NYRCWA6G4WI4AOCYAH/

Metadata

Metadata

Assignees

Labels

api-breakThis issue/PR breaks the API and must wait for a new major versioncomponent-tls

Type

No type

Projects

Status

Implementation in progress

Status

1.0/4.0 SHOULDs

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions