How to enable only specific elliptic curves for key exchange using crypto-policies
Issue
- There is a need to allow only specific elliptic curves for key exchange using
crypto-policiesand disable others. - Removing of the
ECDHEkey exchange protocol from thekey_exchangelist in a custom policy modifier module removes all elliptic curves and does not allow specific curves, such asX25519(curve25519), to be used.
Environment
- Red Hat Enterprise Linux 8
crypto-policies
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.