Security of DH in TLS

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



I'm trying to comprehend the security impact of the different DH implementations on TLS.

The main differences between the implementations are:


Where the ephemeral DH provides forward secrecy, thus provides additional security.


I'm not really sure how the elliptic curves impact the security of DH. I think I've previously read something like, the key size (or public certificate length?) of DH can be smaller, with the use of elliptic curves. So without the use of elliptic curves the key size should be at least 2048, to be considered secure.


Is my assumption correct?

How can I identify the key size/ public certificate length (I'm not sure which is the correct term), to determine the security of DH in TLS?


Can I use the .pem file, used for DH, of my server to determine this?

I've created the .pem file with the following command:


openssl dhparam -out dhparam.pem 4096


and with the following command I believe I can determine the key length:


openssl dhparam -inform PEM -in ./dhparam.pem -check -text

-- 
openssl-users mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux