Re: Hybrid PQC: x25519-mlkem fails in openssl 3.5.5 with default provider
Viktor Dukhovni <[email protected]> Sat, 28 Mar 2026 22:05:19 +1100
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <[email protected]> |
On Sat, Mar 28, 2026 at 02:37:59PM +0530, murugesh pitchaiah wrote:
> Based on the original implementation in BoringSSL, ported from C++ to C,
> refactored, and integrated into the OpenSSL default and FIPS providers.
> Including also the X25519MLKEM768, SecP256r1MLKEM768, SecP384r1MLKEM1024
> TLS hybrid key post-quantum/classical key agreement schemes.
>=20
> (snip)
>=20
> Does that mean even without explicit group set, it's included already in
> TLS 1.3 handshake ? For RSA certificate too ?
Yes, and the certificate is irrelevant. In TLS 1.3 key exchange groups
are negotiated independently of the certificates.
--=20
Viktor. =F0=9F=87=BA=F0=9F=87=A6 =D0=A1=D0=BB=D0=B0=D0=B2=D0=B0 =D0=A3=
=D0=BA=D1=80=D0=B0=D1=97=D0=BD=D1=96!
--=20
You received this message because you are subscribed to the Google Groups "=
openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msg=
id/openssl-users/ace170Dd2YSU6oN1%40chardros.imrryr.org.