Re: dovecot - Generate DH parameters (wiki vs. journal output mismatch)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



On Tue, 19 Feb 2019 at 09:07, David C. Rankin
<drankinatty@xxxxxxxxxxxxxxxxxx> wrote:
>   The wiki https://wiki.archlinux.org/index.php/Dovecot#Generate_DH_parameters
> shows:
>
> Generate DH parameters
>
> To generate a new DH parameters file (this will take very long):
>
> # openssl dhparam -out /etc/dovecot/dh.pem 4096
>
>
>   The journal message shows:
>
> dd if=/var/lib/dovecot/ssl-parameters.dat bs=1 skip=88 | openssl dhparam
> -inform der > /etc/dovecot/dh.pem
>
> (which takes a fraction of a second)
>
>   Why the difference? It doesn't seem to matter.

For what it's worth, you should probably be using the well known dhparams,
see https://wiki.mozilla.org/Security/Server_Side_TLS#Pre-defined_DHE_groups

Our wiki needs to be updated.



[Index of Archives]     [Linux Wireless]     [Linux Kernel]     [ATH6KL]     [Linux Bluetooth]     [Linux Netdev]     [Kernel Newbies]     [Share Photos]     [IDE]     [Security]     [Git]     [Netfilter]     [Bugtraq]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Linux ATA RAID]     [Samba]     [Device Mapper]

  Powered by Linux