X25519 for TLS

Curve25519, designed by Prof. Dan Bernstein, is one of the two curves selected by the CFRG for recommendation. When compared to P-256, the most commonly used curve in TLS today, it admits simpler, faster implementations that are more naturally resistant to side-channels. In Chrome 50, we will be adding support for X25519, the Diffie-Hellman primitive over curve25519, to TLS.


Editor's draft

Status in Chromium


Enabled by default (tracking bug) in:

  • Chrome for desktop release 50
  • Chrome for Android release 50
  • Android WebView release 50

Consensus & Standardization

After a feature ships in Chrome, the values listed here are not guaranteed to be up to date.

  • No public signals
  • In development
  • No public signals
  • No signals


Last updated on 2017-06-14