# Automated insertion of ECDSA allow list?

**URL:** https://community.letsencrypt.org/t/automated-insertion-of-ecdsa-allow-list/158246
**Category:** Feature Requests
**Created:** [August 20, 2021, 4:21pm UTC](https://community.letsencrypt.org/t/automated-insertion-of-ecdsa-allow-list/158246 "2021-08-20T16:21:06Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![orangepizza](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/orangepizza/32/19597_2.png) [@orangepizza](https://community.letsencrypt.org/u/orangepizza)
#### Post date: [August 20, 2021, 4:21pm UTC](https://community.letsencrypt.org/t/automated-insertion-of-ecdsa-allow-list/158246/1 "2021-08-20T16:21:06Z")

</div>

it looks like ecdsa allow list is currently manual process. but as it takes some time to automated to add account automatically as ecdsa-allowed when account meet some criteria?  
like accounts registered with email _[ecdsa+username@domain.com](mailto:ecdsa+username@domain.com)_ (this will sent to inbox [username@domain.com](mailto:username@domain.com)) are automatically inserted to ECDSA allow list, or if completely static code path wanted it could process as if it's in allow list when account key is RSA key that use unusual but secure parameter, like e=65539 . not sure standard ec key have this kind of free parameter to set.

---

<div class="post-metadata">

### Author: ![aarongable](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/aarongable/32/42043_2.png) [@aarongable](https://community.letsencrypt.org/u/aarongable)
#### Post date: [August 20, 2021, 5:34pm UTC](https://community.letsencrypt.org/t/automated-insertion-of-ecdsa-allow-list/158246/2 "2021-08-20T17:34:42Z")

</div>

We're sticking with the manual process for now, but hope to remove the allow-list entirely and open up ECDSA issuance for everyone in the near future.

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [August 20, 2021, 5:37pm UTC](https://community.letsencrypt.org/t/automated-insertion-of-ecdsa-allow-list/158246/3 "2021-08-20T17:37:14Z")

</div>

@aarongable May I ask what kind of "checklist" there is before you can open up ECDSA issuance for everybody? Just being curious here.

---

<div class="post-metadata">

### Author: ![Nummer378](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nummer378/32/49862_2.png) [@Nummer378](https://community.letsencrypt.org/u/Nummer378)
#### Post date: [August 20, 2021, 5:47pm UTC](https://community.letsencrypt.org/t/automated-insertion-of-ecdsa-allow-list/158246/4 "2021-08-20T17:47:21Z")

</div>

I believe by making this opt-in initially they want to ensure that:

- There are no issues with ECDSA issuance, e.g no large scale bugs in boulder, and client implementations that work correctly (with ECC)
- ISRG Root X2 reaches (most) root programs. For example, Mozilla is currently blocked at waiting for discussion.

---

<div class="post-metadata">

### Author: ![aarongable](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/aarongable/32/42043_2.png) [@aarongable](https://community.letsencrypt.org/u/aarongable)
#### Post date: [August 21, 2021, 12:37am UTC](https://community.letsencrypt.org/t/automated-insertion-of-ecdsa-allow-list/158246/5 "2021-08-21T00:37:03Z")

</div>

In addition to the above, we're trying to be careful to not rock the boat by changing too many things at the same time. In particular, we'd like to get past the DST Root CA X3 expiration in September and ensure that that goes smoothly before making other sweeping changes.

---

<div class="post-metadata">

### Author: ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)
#### Post date: [September 20, 2021, 12:37am UTC](https://community.letsencrypt.org/t/automated-insertion-of-ecdsa-allow-list/158246/6 "2021-09-20T00:37:52Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
