@varx Btw, another option is dropping support for RSA entirely which would give me access to ECDH. Getting a shared secret from two keypairs for free feels like a superpower and I don't know how to do that with RSA. It might be the most compelling reason I've seen yet for why ECC is better than RSA.