Join GitHub today
GitHub is home to over 50 million developers working together to host and review code, manage projects, and build software together.Sign up
Need to change to 2048 bit DH groups in TLS for notifications #229
Given the recent concerns over possible breaks of 1024 bit DH keys we need to make sure our openssl configuration for DHE_PSK_WITH_AES_256_GCM_SHA384 uses a 2048 bit DH key. Note that we don't currently appear to have the option to switch to ECDHE since OpenSSL doesn't appear to support it for PSK with AES_256_GCM.