Re: Hybrid PQC: x25519-mlkem fails in openssl 3.5.5 with default provider

Viktor Dukhovni <[email protected]> Sat, 28 Mar 2026 22:01:46 +1100
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <[email protected]>
On Sat, Mar 28, 2026 at 01:06:59PM +0530, murugesh pitchaiah wrote:

> One more question.  Incase my requirement is old RSA certs plus only ML-K=
EM
> for key exchange alone, shall I use the hybrid x25519mlkem768 just like
> below ctx set group code, with existing RSA certificate in both client an=
d
> server?
>=20
> SSL_CTX_set1_groups_list(ctx, "X25519MLKEM768");

No, because the default group list already includes X25519MLKEM,
but also includes other groups that improve interoperability.
That setting is unnecessary.

> If yes, is it natively supported with default provider in openssl 3.5.5? =
Or
> need oqs provider?

You do not need the OQS provider, and it is best avoided in production
configuratons.

--=20
    Viktor.  =F0=9F=87=BA=F0=9F=87=A6 =D0=A1=D0=BB=D0=B0=D0=B2=D0=B0 =D0=A3=
=D0=BA=D1=80=D0=B0=D1=97=D0=BD=D1=96!

--=20
You received this message because you are subscribed to the Google Groups "=
openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msg=
id/openssl-users/ace1GvN8hsL9wrO_%40chardros.imrryr.org.