[Bug 59087] DH parameters with too small prime lengths used with openssl < 1.0.2

2016-03-04 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=59087 Yann Ylavic changed: What|Removed |Added Status|RESOLVED|REOPENED Summary|DH parameter

[Bug 59087] DH parameters with too small prime lengths used with openssl < 1.0.2

2016-03-04 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=59087 --- Comment #8 from Yann Ylavic --- (In reply to Eric Covener from comment #7) > > move to DOCS maybe to capture it? I didn't follow too closely. Done, will see how we can document SSLCertificateFile accordingly. -- You are receiving this m

[Bug 59087] DH parameters with too small prime lengths used with openssl < 1.0.2

2016-03-04 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=59087 --- Comment #9 from Björn Jacke --- It is not possible to iterate once over the certs and use the strongest cert for the DH param size calculation? But in any case: If we *know* that we mis-calculate the DH param size with openssl 1.0.1, then

[Bug 59087] DH parameters with too small prime lengths used with openssl < 1.0.2

2016-03-04 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=59087 Yann Ylavic changed: What|Removed |Added CC||ylavic@gmail.com --- Comment #10 fro

Re: [Bug 59087] DH parameters with too small prime lengths used with openssl < 1.0.2

2016-03-04 Thread Tom
Open SSL 1.0.1 is being retired at the end of the year, so changes are unlikely. -- Tom Sent from my phone. On 4 March 2016 16:21:07 GMT+00:00, bugzi...@apache.org wrote: >https://bz.apache.org/bugzilla/show_bug.cgi?id=59087 > >Yann Ylavic changed: > > What|Removed