Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

crypto/tls: FIPS 140-3 modes reject ECDSA w/ curve P-521/SHA-512 in TLS [1.24 backport] #72823

Open
gopherbot opened this issue Mar 12, 2025 · 1 comment
Labels
CherryPickApproved Used during the release process for point releases
Milestone

Comments

@gopherbot
Copy link
Contributor

gopherbot commented Mar 12, 2025

@FiloSottile requested issue #71757 to be considered for backport to the next 1.24 minor release.

@gopherbot please open a backport change to Go 1.24 to revert the removal of P-521 in Go+BoringCrypto mode by cherry-picking CL 657095, as discussed above.

@gopherbot gopherbot added the CherryPickCandidate Used during the release process for point releases label Mar 12, 2025
@gopherbot gopherbot added this to the Go1.24.2 milestone Mar 12, 2025
@gopherbot
Copy link
Contributor Author

Change https://go.dev/cl/657135 mentions this issue: [release-branch.go1.24] crypto/tls: allow P-521 in FIPS 140-3 mode and Go+BoringCrypto

@dr2chase dr2chase added the CherryPickApproved Used during the release process for point releases label Mar 12, 2025
@gopherbot gopherbot removed the CherryPickCandidate Used during the release process for point releases label Mar 12, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CherryPickApproved Used during the release process for point releases
Projects
None yet
Development

No branches or pull requests

2 participants