OpenSSL Communities

Disabling support of explicit curves in OpenSSL via compilation options

Dmitry BelyavskyDmitry Belyavsky Tue 13 Jan 2026 7:54AMPublicSeen by 29

Using explicit Elliptic curves is discouraged by security reasons and is disabled in RHEL-based distributions via patch.

I think it would be better to have a configure option for this purpose

https://github.com/openssl/openssl/pull/29639
is an implementation based on
https://github.com/beldmit/openssl/commit/6a2b78bca595435fcbf72d7b2c8bec004d555016

Dmitry Belyavsky

Add a configure option to disable support of explicit elliptic curves

poll by Dmitry Belyavsky Closed Mon 19 Jan 2026 7:00AM

What is this poll about?

Why is this important?

What are you asking people to do?

Choose the option(s) you favor.

Results

ResultsOption% of pointsVoters
Yes, in 4.09314Paul YangTomas MrazRichard Levitte (OpenSSL)Sasha NedvedickyPaul DaleShane LontisViktor DukhovniAlicja KarioNorbert PócsTim HudsonDmitry BelyavskyTodd ShortSimo SorceMatt Caswell
Yes, after 4.071Neil Horman
No00 
Undecided13Tim HudsonRichard Levitte (individual)Anton ArapovFrederik Wedel-HeinenTom CosgroveJon EricsonBernd EdlingerKurt RoeckxTomas VavraDavid von OheimbEugene SyromiatnikovNikola PajkovskýKaterina Micova

15 of 28 votes cast (53% participation)

Dmitry Belyavsky

Dmitry BelyavskyTue 13 Jan 2026 7:55AM

Yes, in 4.0

If necessary, I'm volunteering adapting the RHEL patch for this purpose

Paul Yang

Paul YangTue 13 Jan 2026 7:55AM

Yes, in 4.0

ASAP

Shane Lontis

Shane LontisTue 13 Jan 2026 7:55AM

Yes, in 4.0

Being able to remove it would be good for security purposes. Whether it makes it to 4.0 or not it probably should be done.

Tomas Mraz

Tomas MrazTue 13 Jan 2026 7:55AM

Yes, in 4.0

I think there is still some time to get things into 4.0 and this is not particularly complicated change. The question is whether explicit curve support should be disabled by default or not. If it makes into 4.0, it could be disabled by default actually.

Norbert Pócs

Norbert PócsTue 13 Jan 2026 7:55AM

Yes, in 4.0

Sounds good to me and the change doesn't sound that difficult for 4.0

Matt Caswell

Matt CaswellTue 13 Jan 2026 7:55AM

Yes, in 4.0

I have no objection to this.

Neil Horman

Neil HormanTue 13 Jan 2026 7:55AM

Yes, after 4.0

I'm not opposed to adding such a configuration feature, but I think its a little late in the 4.0 development cycle to be adding it

Dmitry Belyavsky

Dmitry BelyavskyWed 14 Jan 2026 8:11PM

@Neil Horman I have just pushed the changes
https://github.com/openssl/openssl/pull/29639

Tim Hudson

Tim HudsonTue 13 Jan 2026 7:55AM

Yes, in 4.0

At least this as an option, but would prefer it on by default (i.e. explicit curves disabled by default)

Load More