|Submitter||Diff||Changes||Open Issues||Last Updated|
|Error loading review requests:|
We currently leave the default groups enabled, which could be problematic on some systems, particularly for performance. When doing so, we should also ensure that we call SSL_SendAdditionalKeyShares so that we generate P-256 shares as well as 25519 shares. That will affect TLS 1.3 when that's enabled, and we could miss it (there is a theory that all the servers will have 25519, but that's not certain yet). Recommended groups and their order: 25519, P-256, P384, FFDHE2048, FFDHE3072.
Comment on attachment 8794709 [details] Bug 1304926 - Enable specific named groups, https://reviewboard.mozilla.org/r/81040/#review79758 LGTM once enough of bug 1304919 lands.
Pushed by firstname.lastname@example.org: https://hg.mozilla.org/integration/mozilla-inbound/rev/27e8b32dea3e Enable specific named groups, r=keeler