OpenSSL Communities

Disabling support of explicit curves in OpenSSL via compilation options

DB Dmitry Belyavsky Tue 13 Jan 2026 7:54AM Public Seen by 27

Using explicit Elliptic curves is discouraged by security reasons and is disabled in RHEL-based distributions via patch.

I think it would be better to have a configure option for this purpose

https://github.com/openssl/openssl/pull/29639
is an implementation based on
https://github.com/beldmit/openssl/commit/6a2b78bca595435fcbf72d7b2c8bec004d555016

DB

Add a configure option to disable support of explicit elliptic curves

poll by Dmitry Belyavsky Closed Mon 19 Jan 2026 7:00AM

What is this poll about?

Why is this important?

What are you asking people to do?

Choose the option(s) you favor.

Results

Results Option % of points Voters
Yes, in 4.0 93 14 NP VD PY RL TH DB SN PD SL AK TM TS SS MC
Yes, after 4.0 7 1 NH
No 0 0  
Undecided 13 BE ES KR TC TV DVO NP RL TH JE FW KM AA

15 of 28 votes cast (53% participation)

DB

Dmitry Belyavsky Tue 13 Jan 2026 7:55AM

Yes, in 4.0

If necessary, I'm volunteering adapting the RHEL patch for this purpose

PY

Paul Yang Tue 13 Jan 2026 7:55AM

Yes, in 4.0

ASAP

SL

Shane Lontis Tue 13 Jan 2026 7:55AM

Yes, in 4.0

Being able to remove it would be good for security purposes. Whether it makes it to 4.0 or not it probably should be done.

TM

Tomas Mraz Tue 13 Jan 2026 7:55AM

Yes, in 4.0

I think there is still some time to get things into 4.0 and this is not particularly complicated change. The question is whether explicit curve support should be disabled by default or not. If it makes into 4.0, it could be disabled by default actually.

NP

Norbert Pócs Tue 13 Jan 2026 7:55AM

Yes, in 4.0

Sounds good to me and the change doesn't sound that difficult for 4.0

MC

Matt Caswell Tue 13 Jan 2026 7:55AM

Yes, in 4.0

I have no objection to this.

NH

Neil Horman Tue 13 Jan 2026 7:55AM

Yes, after 4.0

I'm not opposed to adding such a configuration feature, but I think its a little late in the 4.0 development cycle to be adding it

DB

Dmitry Belyavsky Wed 14 Jan 2026 8:11PM

@Neil Horman I have just pushed the changes
https://github.com/openssl/openssl/pull/29639

TH

Tim Hudson Tue 13 Jan 2026 7:55AM

Yes, in 4.0

At least this as an option, but would prefer it on by default (i.e. explicit curves disabled by default)

Load More