Skip to content

crypto/tls: support CNSA 2.0 profile #79406

Description

@cameronjwest98-ux

CNSA 2.0, which is utilized as a standard for some government solutions, has the requirements for TLS 1.3 with the cipher suite, TLS_AES_256_GCM_SHA384
With the removal of cipher selection going from 1.2 to 1.3, this blocks many of the gov clients.
I have seen this issue brought up as early as 2018.
Is there a proposed solution or recommended work around so these requirements can be met?

Many of the previous concerns were in accordance to the FIPS requirements.

previous issue: #29349

Metadata

Metadata

Assignees

No one assigned

    Labels

    LibraryProposalIssues describing a requested change to the Go standard library or x/ libraries, but not to a toolNeedsDecisionFeedback is required from experts, contributors, and/or the community before a change can be made.

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions