Re: [openssl-users] DH parameters [was: Vulnerability >> logjam << downgrades TLS connections to 512 Bit]

2015-05-22 Thread Jeffrey Walton
On Fri, May 22, 2015 at 5:20 AM, Walter H. wrote: > Hello > > On 22.05.2015 08:30, Jeffrey Walton wrote: >> >> Or are you talking about server certificates with fixed DH parameters? > > can you please tell me more about this? They have a DH group called out by parameters (an not by name as in the

[openssl-users] FIPs validation questions

2015-05-22 Thread Philip Bellino
Hello, We use OpenSSL-1.0.2a and FIPS 2.0.9 and have questions we need to answer in conjunction with the FIPS validation process. One question is whether SHA1 accepts NULL (zero-length) messages? I couldn't find anything on the OpenSSL wiki so I thought I'd ask here. Also, another questions

[openssl-users] DH parameters [was: Vulnerability >> logjam << downgrades TLS connections to 512 Bit]

2015-05-22 Thread Walter H.
Hello On 22.05.2015 08:30, Jeffrey Walton wrote: Or are you talking about server certificates with fixed DH parameters? can you please tell me more about this? how do I have to create the certificate request? (using debian 7 latest updates installed: 'apt-get update & apt-get upgrade' has n

Re: [openssl-users] What key length is used for DHE by default ?

2015-05-22 Thread Matt Caswell
On 22/05/15 11:11, Nayna Jain wrote: > Hi, > > With the latest logjam attack, as I was trying to verify if my server > (lighttpd) accepts DHE_xxx ciphers, I saw that it accepted and I > didn't do any configuration setting done for DH parameters explicitly. > > But I couldn't verify what is th

[openssl-users] What key length is used for DHE by default ?

2015-05-22 Thread Nayna Jain
Hi, With the latest logjam attack, as I was trying to verify if my server (lighttpd) accepts DHE_xxx ciphers, I saw that it accepted and I didn't do any configuration setting done for DH parameters explicitly. But I couldn't verify what is the key length did it use by default 512/1024/2048 ?

Re: [openssl-users] Vulnerability >> logjam << downgrades TLS connections to 512 Bit

2015-05-22 Thread Jakob Bohm
On 22/05/2015 08:30, Jeffrey Walton wrote: On Fri, May 22, 2015 at 1:55 AM, Jakob Bohm wrote: On 22/05/2015 07:18, Jeffrey Walton wrote: On Fri, May 22, 2015 at 12:51 AM, Jakob Bohm wrote: On 22/05/2015 03:57, Jeffrey Walton wrote: As an additional change for 1.0.2c or later (no need to del