[gnutls-devel] weak dh issue

Nikos Mavrogiannopoulos n.mavrogiannopoulos at gmail.com
Wed May 20 17:10:20 CEST 2015


According to https://weakdh.org/ there is a new attack which relies on
clients accepting weak DHE parameters. GnuTLS is unaffected by this
attack, and it seems like a good choice that we always imposed higher
standards for parameters than other implementations despite the many
bug reports [0] in the past.

[0]. http://www.gnutls.org/faq.html#prime-not-acceptable



More information about the Gnutls-devel mailing list