Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

@swalkinshaw
Copy link
Member

This was needed to prevent Logjam attacks but those only applied to DHE cyphers which haven't been supported in Trellis for 2 years.

@swalkinshaw
Copy link
Member Author

Confirmed we can remove these thanks to SSL Labs:
image

Generating the DH params is one of the slowest parts of provisioning a server with Trellis (and even more annoying in dev when you want to test local SSL) so removing it should be noticeable.

This was needed to prevent Logjam attacks but those only applied to DHE
cyphers which haven't been supported in Trellis for 2 years.
@swalkinshaw swalkinshaw merged commit 49f5a3e into master Dec 4, 2021
@swalkinshaw swalkinshaw deleted the remove-ssl_dhparam branch December 4, 2021 00:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants