Re: Forward secrecy (was: Certificate Error)

2013-12-23 Thread Viktor Dukhovni
On Tue, Dec 24, 2013 at 03:00:37AM +1100, nanotek wrote: > >We obviously don't know which is stronger against hypothetical > >unpublished attacks, EDH at 2048-bits or the P-256 curve. Feel > >free to roll the dice. Against publically known attacks P-256 is > >both more secure and more computatio

RE: Forward secrecy (was: Certificate Error)

2013-12-23 Thread nanotek
On 24/12/2013 2:09 AM, Viktor Dukhovni wrote: On Tue, Dec 24, 2013 at 01:29:38AM +1100, nanotek wrote: Still, might be a good time to create my own CA and upgrade to 4096 bit keys/certificates You can deploy 4096-bit RSA key if it makes you feel more cool, but there is little point in going b