https://community.letsencrypt.org/t/when-choosing-an-elliptic-curve-look-for-a-safe-curve/161837
7.1.3.1.2 ECDSA The CA SHALL indicate an ECDSA key using the id‐ecPublicKey (OID: 1.2.840.10045.2.1) algorithm identifier. The parameters MUST use the namedCurve encoding.
For P‐256 keys, the namedCurve MUST be secp256r1 (OID: 1.2.840.10045.3.1.7). For P‐384 keys, the namedCurve MUST be secp384r1 (OID: 1.3.132.0.34).