CECPQ1: change from named curve to ciphersuite. This is easier to deploy, and more obvious. This commit reverts a few pieces of e25775bc, but keeps most of it. Change-Id: If8d657a4221c665349c06041bb12fffca1527a2c Reviewed-on: https://boringssl-review.googlesource.com/8061 Reviewed-by: Adam Langley <agl@google.com>
diff --git a/ssl/ssl_lib.c b/ssl/ssl_lib.c index a27d430..3b8cff7 100644 --- a/ssl/ssl_lib.c +++ b/ssl/ssl_lib.c
@@ -1725,6 +1725,9 @@ mask_k |= SSL_kECDHE; } + /* CECPQ1 ciphers are always acceptable if supported by both sides. */ + mask_k |= SSL_kCECPQ1; + /* PSK requires a server callback. */ if (ssl->psk_server_callback != NULL) { mask_k |= SSL_kPSK;