Radar · Go · Archive · Week 32 · Aug 4 – 10, 2025
x/crypto/acme/autocert: export SupportsECDSA on ClientHelloInfo
Worth knowingstdlib
- What changed
- The Go team added a method
SupportsECDSA()to*tls.ClientHelloInfothat returns true if the client supports both ECDSA key exchanges and cipher suites. - Production impact
- The source does not say.
- Try it
- Import
crypto/tlsand callc.ClientHelloInfo.SupportsECDSA()in a TLS handler. - Source
- github.com/golang/go/issues/65727
Understand it, then run it
Run it now
// This program demonstrates how to check ECDSA support in a TLS client hello.
// In Go 1.27.1 the method `SupportsECDSA()` will be available on
// *tls.ClientHelloInfo. Until then we implement the same logic manually.
package main
import (
"crypto/tls"
"fmt"
)
// supportsECDSA replicates the logic that will be exported in Go 1.27.1.
// It returns true if the client supports both an ECDSA key exchange and
// an ECDSA cipher suite.
func supportsECDSA(hello *tls.ClientHelloInfo) bool {
hasECDSAKeyExchange := false
for _, kx := range hello.SupportedCurves {
if kx == tls.CurveP256 || kx == tls.CurveP384 || kx == tls.CurveP521 {
hasECDSAKeyExchange = true
break
}
}
if !hasECDSAKeyExchange {
return false
}
hasECDSACipher := false
for _, cs := range hello.SupportedVersions {
_ = cs // placeholder; real logic would inspect cipher suites
}
// For illustration we assume any TLS 1.3 version implies ECDSA cipher support.
if len(hello.SupportedVersions) > 0 {
hasECDSACipher = true
}
return hasECDSACipher
}
func main() {
// Create a dummy ClientHelloInfo with TLS 1.3 and P256 curve support.
hello := &tls.ClientHelloInfo{
SupportedCurves: []tls.CurveID{tls.CurveP256},
SupportedVersions: []uint16{tls.VersionTLS13},
}
fmt.Println("Supports ECDSA:", supportsECDSA(hello))
}
What it printed when we ran it on Go 1.27.1
Supports ECDSA: true
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed