cross-posted from: lemmy.bestiver.se/post/704939
No offense but CAs still don’t support ed25519, a now 20 year old ECDSA standard that everyone uses basically everywhere else, including FIPS.
Although tbf I’m sure the NSA could yolo PKI in an “emergency” situation anyway by compromising a CA, though I don’t think that would happen unless its literally WWIII.
solrize@lemmy.ml 5 months ago
Is this for quantum resistance? The certificates would be pretty large and they don’t give a key agreement scheme, just signatures. They are clever but to deploy them on internet scale would take a lot of software changes in everything.