- Use RSA until 25519/448 land in TLS
- Switch to ECDSA in the interim
Personally, I would switch even though ECDSA isn't great.The concerns over P-256 and P-384 are more academic than anything: They're hard to implement safely and without side-channels. Read: hard, not impossible.
You shouldn't be writing your own ECDSA implementation, however. That'd be foolhardy.
EDIT: I use secp384r1 for signing random_compat, so if anyone gets bit by this recommendation, I will too: https://github.com/paragonie/random_compat/blob/master/dist/...