4 ms·
Not sure why you have to wait. I use ChaCha in production in JDK 8: https://github.com/bcgit/bc-java/blob/master/core/src/main/java/org/bouncycastle/crypto/engi
by samch 10y ago
Not sure why you have to wait. I use ChaCha in production in JDK 8:
https://github.com/bcgit/bc-java/blob/master/core/src/main/java/org/bouncycastle/crypto/engines/ChaChaEngine.java https://github.com/bcgit/bc-java/blob/master/core/src/main/j...
Why would native be any better? I would think that as long as the implementation matches the reference it wouldn't matter.
- theandrewbailey 10y agoLast weekend, I added Bouncy Castle as the security provider in my dev environment, but my server did not show ChaCha20 in the list of available TLS ciphers. I was not convinced that my server was even using BC. Knowing that if you don't know what you're doing and mess around with crypto too much that you can get burned, I gave up. ECDHE RSA AES GCM for now.
- samch 10y agoI think I see where you're coming on that. For most of my applications, I terminate TLS connections with nginx. I do use ChaCha for high-speed encryption in other areas, though. The BC libraries have always worked great for me.