Conversation

What browsers/percent of users/legacy clients can't do ECDSA certs these days? A few years back AWS Cloudfront couldn't, but I assume that's been upgraded? Anything else?
6
2
Replying to and
DHE ciphers aren't supported with ECDSA. If you use the Mozilla Intermediate cipher configuration with ECDSA, you end up using 3 ciphers for TLS < 1.3: ECDHE-ECDSA-AES256-GCM-SHA384 ECDHE-ECDSA-CHACHA20-POLY1305 ECDHE-ECDSA-AES128-GCM-SHA256 Matches the 3 usual TLS 1.3 ciphers.