list.sys4.de
Sign In Sign Up
Manage this list Sign In Sign Up

Keyboard Shortcuts

Thread View

  • j: Next unread message
  • k: Previous unread message
  • j a: Jump to all threads
  • j l: Jump to MailingList overview

dane-users

Thread Start a new thread
Download
Threads by month
  • ----- 2025 -----
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2024 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2023 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2022 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2021 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2020 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2019 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2018 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2017 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2016 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2015 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
dane-users@list.sys4.de

October 2025

  • 1 participants
  • 1 discussions
Please ensure your servers can handle "post-quantum" STARTTLS
by Viktor Dukhovni 26 Oct '25

26 Oct '25
Recent releases of various TLS libraries are enabling support for "post-quantum" key agreement. For example, in OpenSSL 3.5 the default client behaviour is to send TLS 1.3 "keyshares" for both the hybrid "post-quantum" X25519MLKEM768 and for the "classical" X25519. The size of the resulting TLS Client Hello message is close to 1500 bytes and it often splits across multiple TCP segments. This may run into friction with "middlebox" TLS inspection, or with server TLS stack implementations, resulting in failure (often timeouts) to complete the TLS handshake, which hangs or aborts are the TLS Client Hello. It is expected that use of these algorithms by TLS clients will continue to grow and it is best to take action now and not wait for problems to become urgent. If you have access to a computer with OpenSSL 3.5 (or later) you can check your server with: $ host=your.server-fqdn.example $ (sleep 2; printf 'QUIT\r\n') | openssl s_client -starttls smtp -connect $host:25 \ -groups "*X25519MLKEM768:*X25519:P-256:ffdhe3072" -state -brief If this hangs after printing "SSL_connect:SSLv3/TLS write client hello", you likely have a problem, to confirm, you can try again with: $ host=your.server-fqdn.example $ (sleep 2; printf 'QUIT\r\n') | openssl s_client -starttls smtp -connect $host:25 \ -groups "X25519MLKEM768:*X25519:P-256:ffdhe3072" -state -brief and if that succeeds promptly, it is appropriate to take action to find out what's causing the problem, and take steps to remediate it. -- Viktor. 🇺🇦 Слава Україні!
1 0
0 0

HyperKitty Powered by HyperKitty version 1.3.8.