Re: [Dovecot] DH parameter length too small?

2013-11-02 Thread Timo Sirainen
On 14.10.2013, at 19.08, Jörg Lübbert j.luebb...@kaladix.org wrote: from my understanding, using 1024bit DH parameters results in a not sufficiently secure key exchange for DH(E). Therefore I think it would be advisable to have parameters of at least 2048bit . In fact, I would see a great

[Dovecot] DH parameter length too small?

2013-10-14 Thread Jörg Lübbert
Hello, from my understanding, using 1024bit DH parameters results in a not sufficiently secure key exchange for DH(E). Therefore I think it would be advisable to have parameters of at least 2048bit . In fact, I would see a great benefit in chosing parameter length arbitrarily. I also do not

Re: [Dovecot] DH Parameter

2013-09-21 Thread Timo Sirainen
On 10.9.2013, at 22.57, Dimi - 00t...@gmail.com wrote: Hi! Is there any possibility to let dovecot serve 1024 Bit DH Parameters at SSL/TLS-connections? Is it possible to replace /var/lib/dovecot/ssl-parameters.ssl with DH-parameter generated by openssl? If not: Are there any plans to

[Dovecot] DH Parameter

2013-09-12 Thread Dimi -
Hi! Is there any possibility to let dovecot serve 1024 Bit DH Parameters at SSL/TLS-connections? Is it possible to replace /var/lib/dovecot/ssl-parameters.ssl with DH-parameter generated by openssl? If not: Are there any plans to implement that? Thank you!