Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove ssl_dhparam and Diffie-Hellman group #1326

Merged
merged 1 commit into from
Dec 4, 2021
Merged

Conversation

swalkinshaw
Copy link
Member

This was needed to prevent Logjam attacks but those only applied to DHE cyphers which haven't been supported in Trellis for 2 years.

@swalkinshaw
Copy link
Member Author

Confirmed we can remove these thanks to SSL Labs:
image

Generating the DH params is one of the slowest parts of provisioning a server with Trellis (and even more annoying in dev when you want to test local SSL) so removing it should be noticeable.

This was needed to prevent Logjam attacks but those only applied to DHE
cyphers which haven't been supported in Trellis for 2 years.
@swalkinshaw swalkinshaw merged commit 49f5a3e into master Dec 4, 2021
@swalkinshaw swalkinshaw deleted the remove-ssl_dhparam branch December 4, 2021 00:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant