Skip to content

Temporary PR for #1800 squash check#1934

Closed
mxsasha wants to merge 7 commits intosslyzefrom
ncsc2025rb
Closed

Temporary PR for #1800 squash check#1934
mxsasha wants to merge 7 commits intosslyzefrom
ncsc2025rb

Conversation

@mxsasha
Copy link
Collaborator

@mxsasha mxsasha commented Feb 18, 2026

No description provided.

Some key changes:
* FFDHE2024 -> insufficient, others -> phase out
* Remove ECDHE/DHE min key size - this is superfluous
* Update SHA2 key exchange check to new requirements (must reject SHA1 and older, sha224 to phase out).
* Update cert requirements, including RSA phase out for 2048
* Add RSA-PKCS check
* Update client initiated renegotiation limits, incl DB changes for 3 states now
* Add support for EMS test
* Check all non-root certs for sighash/key size/curve.
This is a bit wonky, but it's fine, it's only for the dev4 test period
@mxsasha mxsasha changed the base branch from main to sslyze February 18, 2026 13:35
@mxsasha mxsasha closed this Feb 18, 2026
@mxsasha mxsasha deleted the ncsc2025rb branch February 18, 2026 13:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant