On Thu Mar 13 20:12:38 2014, [email protected] wrote: > This is a hard-coded patch to make OpenSSL clients reject connections > which use DHE handshakes with < 1024 bits. >
I should've commented on this before, sorry. I'm currently working on a framework where several security parameters can be configured at both compile time and runtime, including DH parameter sizes. It's still under development at present though. I'll commit it to the master branch when it's more stable. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org ______________________________________________________________________ OpenSSL Project http://www.openssl.org Development Mailing List [email protected] Automated List Manager [email protected]
