When the negotiated ciphersuite is of the type TLS-ECDH-RSA-* (ECDH key exchange + RSA signed certificate), ECDSA signed certificates are accepted, which means that the ciphersuite technically becomes TLS-ECDH-ECDSA. Upstream issue: https://github.com/ARMmbed/mbedtls/issues/1561
Created mbedtls tracking bugs for this issue: Affects: epel-all [bug 1595604] Affects: fedora-all [bug 1595603]
@Andrej I think we should close this. See: https://github.com/ARMmbed/mbedtls/issues/1561#issuecomment-424756997
(In reply to Morten Stevens from comment #2) > @Andrej > > I think we should close this. See: > https://github.com/ARMmbed/mbedtls/issues/1561#issuecomment-424756997 I agree with the upstream analysis, it seems this was classified as a regular bug.