Skip to content

Conversation

@jagerman
Copy link
Member

@jagerman jagerman commented Jan 9, 2026

  • Explicitly disable TLS1.0-1.2 (which aren't used anyway)
  • Remove +SHA256 which does nothing under TLS1.3
  • Remove +AES-128-CCM-8 which does nothing (AES-128-CCM-8 is already implied by TLS1.3, and isn't practically used as TLS-1.3 prefers AES-GCM anyway).
  • Remove unused/unwanted PSK values

None of these changes affect anything in practice over existing libquic connections (which always negotiate "good" values), so this is mainly a clarification/cleanup.

- Explicitly disable TLS1.0-1.2 (which aren't used anyway)
- Remove +SHA256 which does nothing under TLS1.3
- Remove +AES-128-CCM-8 which does nothing (AES-128-CCM-8 is already
  implied by TLS1.3, and isn't practically used as TLS-1.3 prefers
  AES-GCM anyway).
- Remove unused/unwanted PSK values
@jagerman jagerman force-pushed the prune-gnutls-priority branch from 0c515cb to 2edeed1 Compare January 29, 2026 02:22
@jagerman jagerman enabled auto-merge January 29, 2026 02:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants