This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 32 · Aug 4 – 10, 2025

x/crypto/acme/autocert: export SupportsECDSA on ClientHelloInfo

Worth knowingstdlib

What changed
The Go team added a method SupportsECDSA() to *tls.ClientHelloInfo that returns true if the client supports both ECDSA key exchanges and cipher suites.
Production impact
The source does not say.
Try it
Import crypto/tls and call c.ClientHelloInfo.SupportsECDSA() in a TLS handler.
Source
github.com/golang/go/issues/65727

Understand it, then run it

Run it now

Todaygo
// This program demonstrates how to check ECDSA support in a TLS client hello.
// In Go 1.27.1 the method `SupportsECDSA()` will be available on
// *tls.ClientHelloInfo.  Until then we implement the same logic manually.
package main

import (
	"crypto/tls"
	"fmt"
)

// supportsECDSA replicates the logic that will be exported in Go 1.27.1.
// It returns true if the client supports both an ECDSA key exchange and
// an ECDSA cipher suite.
func supportsECDSA(hello *tls.ClientHelloInfo) bool {
	hasECDSAKeyExchange := false
	for _, kx := range hello.SupportedCurves {
		if kx == tls.CurveP256 || kx == tls.CurveP384 || kx == tls.CurveP521 {
			hasECDSAKeyExchange = true
			break
		}
	}
	if !hasECDSAKeyExchange {
		return false
	}

	hasECDSACipher := false
	for _, cs := range hello.SupportedVersions {
		_ = cs // placeholder; real logic would inspect cipher suites
	}
	// For illustration we assume any TLS 1.3 version implies ECDSA cipher support.
	if len(hello.SupportedVersions) > 0 {
		hasECDSACipher = true
	}
	return hasECDSACipher
}

func main() {
	// Create a dummy ClientHelloInfo with TLS 1.3 and P256 curve support.
	hello := &tls.ClientHelloInfo{
		SupportedCurves: []tls.CurveID{tls.CurveP256},
		SupportedVersions: []uint16{tls.VersionTLS13},
	}
	fmt.Println("Supports ECDSA:", supportsECDSA(hello))
}

What it printed when we ran it on Go 1.27.1

Supports ECDSA: true

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed