diff options
author | Kim Alvefur <zash@zash.se> | 2024-07-12 15:06:42 +0200 |
---|---|---|
committer | Kim Alvefur <zash@zash.se> | 2024-07-12 15:06:42 +0200 |
commit | cf446f4188a53396e30f392cae8443fd2eb52f4e (patch) | |
tree | f43b01f92e21559d96ac0bc5a530249dd3afd681 /spec | |
parent | dd657746b490c203d3e503d9359fec9dca6884fd (diff) | |
download | prosody-cf446f4188a53396e30f392cae8443fd2eb52f4e.tar.gz prosody-cf446f4188a53396e30f392cae8443fd2eb52f4e.zip |
core.certmanager: Include ffdhe2048 from RFC 7919 as default DH param
This removes one manual (yet undocumented) step that was supposed to be
done to get a complete 'intermediate' configuration.
This file can be found on the Internet by searching for "ffdhe2048" and
can be verified by comparing the hexadecimal representation of p from
the RFC with the output of `openssl asn1parse`.
Given the preference and prevalence of ECDHE, it seems likely that few
would have noticed this.
Diffstat (limited to 'spec')
0 files changed, 0 insertions, 0 deletions