Files
simple-nixos-mailserver/docs
Martin Weinelt a1532a552f postfix: enable X25519MLKEM768 key exchange
This migrates the key exchange curve group configuration into the OpenSSL
configuration format, which is the only path forward to configure these.

We now prefer a hybrid key exchange for TLS handshake and as a client
we'll send key shares for that and pure X25519, while keeping backwards-
compat for P256 and P384.

The statistics for my personal mail server over the last month show a
clear trend for X25519 key exchanges:

    156 secp384r1
    225 secp256r1
    19541 x25519
2025-11-10 00:31:43 +01:00
..
2025-05-15 16:29:04 +02:00
2021-03-03 08:36:08 +00:00
2025-05-19 16:45:09 +02:00
2023-07-11 19:31:20 +00:00
2021-07-27 19:58:33 +00:00
2020-10-31 08:34:36 +01:00
2025-05-05 20:22:45 +02:00