Document preferences for EC_GROUP_new_by_curve_name. Folks should use curve25519 or P-256 if in doubt. Change-Id: Ie35381ef739744788a80345286f7b21e2bb67c88 Reviewed-on: https://boringssl-review.googlesource.com/26646 Commit-Queue: David Benjamin <davidben@google.com> Commit-Queue: Adam Langley <agl@google.com> Reviewed-by: Adam Langley <agl@google.com> CQ-Verified: CQ bot account: commit-bot@chromium.org <commit-bot@chromium.org>
diff --git a/include/openssl/ec.h b/include/openssl/ec.h index fd35b03..5eee366 100644 --- a/include/openssl/ec.h +++ b/include/openssl/ec.h
@@ -105,10 +105,13 @@ // curve specified by |nid|, or NULL on error. // // The supported NIDs are: -// NID_secp224r1, -// NID_X9_62_prime256v1, -// NID_secp384r1, -// NID_secp521r1 +// NID_secp224r1 (P-224), +// NID_X9_62_prime256v1 (P-256), +// NID_secp384r1 (P-384), +// NID_secp521r1 (P-521) +// +// If in doubt, use |NID_X9_62_prime256v1|, or see the curve25519.h header for +// more modern primitives. OPENSSL_EXPORT EC_GROUP *EC_GROUP_new_by_curve_name(int nid); // EC_GROUP_free frees |group| and the data that it points to.