-
Notifications
You must be signed in to change notification settings - Fork 242
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
A+ with weak DH parameter #80
Comments
It's a grading bug. Thanks for your report. |
"Forward Secrecy" should also be downgraded to "With modern browsers", because one cannot get ROBUST with weak DH parameters. https://dev.ssllabs.com/ssltest/analyze.html?d=www.fastmail.com&s=66.111.4.148&hideResults=on
Is it? |
Hi |
Fixed in 1.16.1, now running on dev.ssllabs.com. I am not grading sites with 1024-bit DH parameters with B yet, given what I saw happen the other day: someone saw a warning about them and then removed them altogether. I need to think about it a bit more. |
It's still possible to get an A+ grade when using 1024 bit DH parameters, that are marked as weak now.
The text was updated successfully, but these errors were encountered: