Multi root certs support

Kris Kwiatkowski kris at amongbytes.com
Fri Mar 11 13:19:06 UTC 2022


Hello,

On my server, I would like to support 2 certificate chains. One chain
would be signed with RSA and the other with EdDSA (so 2 complatelly different
chains with 2 root certificates). Then, let say, new clients that support
EdDSA will choose to use it, otherwise I'll serve RSA for everybody else.

I think a protocol can support such setup (only interested in TLSv1.3), but
is that feature implementated by OpenSSL?

Kind regards,
Kris
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://mta.openssl.org/pipermail/openssl-users/attachments/20220311/3a98ea0c/attachment.htm>


More information about the openssl-users mailing list