Antw: Re: Perfect Forward Secrecy

2013-09-09 Thread Ulrich Windl
Michael Strödermich...@stroeder.com schrieb am 06.09.2013 um 23:33 in Nachricht 522a4a3a.9060...@stroeder.com: Howard Chu wrote: Dieter Klünter wrote: Hi, I wonder whether openldap, if compiled with openssl-1.x, will support PFS. http://en.wikipedia.org/wiki/Perfect_forward_secrecy This

Re: Antw: Re: Perfect Forward Secrecy

2013-09-09 Thread Howard Chu
Ulrich Windl wrote: Michael Strödermich...@stroeder.com schrieb am 06.09.2013 um 23:33 in Nachricht 522a4a3a.9060...@stroeder.com: Howard Chu wrote: Dieter Klünter wrote: Hi, I wonder whether openldap, if compiled with openssl-1.x, will support PFS.

Re: Perfect Forward Secrecy

2013-09-07 Thread Michael Ströder
Howard Chu wrote: Michael Ströder wrote: http://www.openldap.org/doc/admin24/tls.html mentions directive 'TLSEphemeralDHParamFile' whereas slapd.conf(5) mentions 'TLSDHParamFile'. This was noted in ITS#7506. Apparently no one considered it an important enough issue to fix it in the

Perfect Forward Secrecy

2013-09-06 Thread Dieter Klünter
Hi, I wonder whether openldap, if compiled with openssl-1.x, will support PFS. http://en.wikipedia.org/wiki/Perfect_forward_secrecy This issue has been discussed on several mailinglists recently. -Dieter -- Dieter Klünter | Systemberatung http://dkluenter.de GPG Key ID:DA147B05 53°37'09,95N

Re: Perfect Forward Secrecy

2013-09-06 Thread Howard Chu
Dieter Klünter wrote: Hi, I wonder whether openldap, if compiled with openssl-1.x, will support PFS. http://en.wikipedia.org/wiki/Perfect_forward_secrecy This issue has been discussed on several mailinglists recently. It already does, but you have to use the right cipher suites. Also see ITS

Re: Perfect Forward Secrecy

2013-09-06 Thread Michael Ströder
Dieter Klünter wrote: I wonder whether openldap, if compiled with openssl-1.x, will support PFS. http://en.wikipedia.org/wiki/Perfect_forward_secrecy This issue has been discussed on several mailinglists recently. Hmm... Tests on my local system (with OpenSSL 1.0.1e shipped with distribution)

Re: Perfect Forward Secrecy

2013-09-06 Thread Michael Ströder
Howard Chu wrote: Dieter Klünter wrote: Hi, I wonder whether openldap, if compiled with openssl-1.x, will support PFS. http://en.wikipedia.org/wiki/Perfect_forward_secrecy This issue has been discussed on several mailinglists recently. It already does, but you have to use the right cipher

Re: Perfect Forward Secrecy

2013-09-06 Thread Michael Ströder
Howard Chu wrote: Dieter Klünter wrote: Hi, I wonder whether openldap, if compiled with openssl-1.x, will support PFS. http://en.wikipedia.org/wiki/Perfect_forward_secrecy This issue has been discussed on several mailinglists recently. It already does, but you have to use the right cipher

Re: Perfect Forward Secrecy

2013-09-06 Thread Philip Guenther
On Fri, 6 Sep 2013, Michael Ströder wrote: Dieter Klünter wrote: I wonder whether openldap, if compiled with openssl-1.x, will support PFS. http://en.wikipedia.org/wiki/Perfect_forward_secrecy This issue has been discussed on several mailinglists recently. Hmm... Tests on my local

Re: Perfect Forward Secrecy

2013-09-06 Thread Michael Ströder
Philip Guenther wrote: On Fri, 6 Sep 2013, Michael Ströder wrote: Dieter Klünter wrote: I wonder whether openldap, if compiled with openssl-1.x, will support PFS. http://en.wikipedia.org/wiki/Perfect_forward_secrecy This issue has been discussed on several mailinglists recently. Hmm...

Re: Perfect Forward Secrecy

2013-09-06 Thread Quanah Gibson-Mount
--On Friday, September 06, 2013 11:33 PM +0200 Michael Ströder mich...@stroeder.com wrote: Howard Chu wrote: Dieter Klünter wrote: Hi, I wonder whether openldap, if compiled with openssl-1.x, will support PFS. http://en.wikipedia.org/wiki/Perfect_forward_secrecy This issue has been discussed

Re: Perfect Forward Secrecy

2013-09-06 Thread Michael Ströder
Quanah Gibson-Mount wrote: --On Friday, September 06, 2013 11:33 PM +0200 Michael Ströder mich...@stroeder.com wrote: Howard Chu wrote: Dieter Klünter wrote: Hi, I wonder whether openldap, if compiled with openssl-1.x, will support PFS. http://en.wikipedia.org/wiki/Perfect_forward_secrecy

Re: Perfect Forward Secrecy

2013-09-06 Thread Howard Chu
Michael Ströder wrote: http://www.openldap.org/doc/admin24/tls.html mentions directive 'TLSEphemeralDHParamFile' whereas slapd.conf(5) mentions 'TLSDHParamFile'. This was noted in ITS#7506. Apparently no one considered it an important enough issue to fix it in the meantime. -- -- Howard

Re: Perfect Forward Secrecy

2013-09-06 Thread Howard Chu
Michael Ströder wrote: Howard Chu wrote: Dieter Klünter wrote: Hi, I wonder whether openldap, if compiled with openssl-1.x, will support PFS. http://en.wikipedia.org/wiki/Perfect_forward_secrecy This issue has been discussed on several mailinglists recently. It already does, but you have to