Repository navigation
Add TLS 1.3 group information to various SSL/TLS methods and classes #132239
Description
Activity
- addeduntriagedNew issue has not been triaged by the area ownerNew issue has not been triaged by the area owner
on Aug 12, 2026 dotnet-policy-service commented
on Aug 12, 2026 ContributorMore actionsTagging subscribers to this area: @dotnet/area-system-runtime
See info in area-owners.md if you want to be subscribed.dotnet-policy-service commented
on Aug 12, 2026 ContributorMore actionsTagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.Personally, I think exposing the negotiated value for the TLS Supported Group is goodness (ideally using the wire value, a la ciphersuites). But I'd leave out the policy/judgment/classification "IsHybrid", etc. Names like "IsClassic" or "IsTraditional" don't age well.
Also, looks like the hybrid PQC exchanges are no longer draft, they're now IETF RFC 10024 (as of two days ago)
Reacted by Kevin Jones- removeduntriagedNew issue has not been triaged by the area ownerNew issue has not been triaged by the area owner
on Aug 13, 2026 Triage: too late for 11.0, but given how the space evolves, we should look at it for 12.0
It seems that the only platform that surfaces the algorithm is currently OpenSSL, I don't see a way to access it on the other platforms. Shipping a new property that gives useful information only on a single platform is difficult, so we hold off until there is support at least for Schannel.
Pushed a feasibility prototype branch exploring exposing the negotiated TLS 1.3 supported group (named/key-exchange group, including hybrid PQC groups such as
X25519MLKEM768):Branch: https://github.com/rzikm/dotnet-runtime/tree/rzikm/tls-negotiated-group
Highlights:
- New
[CLSCompliant(false)] public enum TlsSupportedGroup : ushortusing IANA wire code points, generated from the IANA registry via a T4 template (same technique asTlsCipherSuite). - New
SslStream.NegotiatedGroupproperty plumbed through per-platformSslConnectionInfo. - OpenSSL implementation via
SSL_get_negotiated_group(3.0+), mapping NID -> IANA value (provider/unknown groups carry the IANA id in the low bits).
Platform feasibility (verified against primary sources): only OpenSSL exposes the negotiated group.
- Windows/Schannel - no
QueryContextAttributesattribute returns it (szExchange/aiExchgive only the key-exchange algorithm), still true on 24H2/Server 2025. - macOS/Network.framework -
sec_protocol_metadataexposes ciphersuite + protocol only. - Android/JSSE+Conscrypt - no public accessor.
On these platforms the property reports
0(unavailable), mirroring howNegotiatedCipherSuiteis platform-gated. This is unapproved public API - the branch is prototype/evidence for API review, not a PR.Note
This comment was generated with the assistance of GitHub Copilot.
- New
As we move toward post quantum crypto, selecting and/or detecting hybrid TLS 1.3 groups (ie; Eliptic Curve Crypto [ECC] + MLKEM) is paramount.
Today, this data is not exposed through various .NET methods, such as the ASP.NET code below.
An update would include some like this:
This would require additional pub enums that include the group value:
This list is not complete, but I doubt you want the entire list; it runs to about 100-ish values.
For bonus points; the following would be useful:
Note: the group is negotiated separately from the ciphersuite in TLS 1.3.
If you want more info - just ask.