We’re trying to determine what KAS is provided by OpenSSL 1.1.1 when using TLS 1.2 with TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384. Is the KAS compliant with NIST SP 800-56a and which scheme is used. E.g., (Cofactor) Full Unified Model ECC CDH, etc. Is the KAS configurable and how? Appreciate your help!!! Regards, --Vlad Malkin, CISSP-ISSEP |