On 06/10/2014 09:47 AM, Kurt Roeckx wrote: > On Mon, Jun 09, 2014 at 04:27:56PM -0700, Rick Andrews wrote: >> AFAIK, Symantec and other CAs have added ECC roots to Mozilla's root store >> using NIST curves. Are any other ECC curves supported by Mozilla, in case >> one wanted to use a different curve? Is the list of supported algorithms and >> key sizes published somewhere? > As far as I know NSS currently only supports P256, P384 and P521.
More exactly NSS can support the initial TLS suite of curves, but almost all users (including mozilla and redhat) of NSS just compile the above 3 NIST curves. > > I would like to add brainpool to that, which should be easy. > > I would also like to see Ed25519, but there is no standard on how > to do that yet. Adding support for any curve within NSS should be relatively straightforward. Convincing particular entities to ship with other curves enable is another matter. bob > > > Kurt >
smime.p7s
Description: S/MIME Cryptographic Signature
-- dev-tech-crypto mailing list dev-tech-crypto@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-tech-crypto