OpenVPN? SSH? Nginx? Apache?
Where are the bugs to make these not use insecure dhparams by default?
OpenVPN? SSH? Nginx? Apache?
Where are the bugs to make these not use insecure dhparams by default?
> Breaking a second 1024-bit prime would allow passive eavesdropping on connections to nearly 20% of the top million HTTPS websites.
I'll point out that agwa's comment is relevant here in mitigation. Without any control over what primes are used on the server side, the only resolution would be to detect the server is using such a prime and then avoid communicating with that server until they've patched their systems. Perhaps someone who knows more about this could comment on how we could go about notifying websites they are using venerable primes?
Maybe a Chrome plugin attached to an IPFS client could be one method to warn on access of sites using default primes.
Here is a comment written in the vars configuration file for easy-rsa 2.2.2:
# Increase this to 2048 if you
# are paranoid. This will slow
# down TLS negotiation performance
# as well as the one-time DH parms
# generation process.
export KEY_SIZE=1024
So if you used easy-rsa version 2.2.2 or previous to generate your diffie hellman key for the server, and didn't increase the default size in the vars file before doing so, your server uses a 1024 bit diffie hellman key.(I'm not sure Apache even defaults to enabling forward secrecy by default, without which you're not exposed to DH at all).
As of Apache 2.4.7, the default DH parameters have the same number of bits as your RSA key, and since CAs have required at least 2048 bit RSA for a few years now, you'll be fine.
OpenSSH does ship parameters that are larger than 1024 bits (in addition to 1024 bit parameters), and with the "group-exchange" kex, sufficiently-secure parameters should be negotiated with clients, although I haven't looked too closely to see if this might be vulnerable to downgrade attacks.
Last I looked nginx used fixed 1024 bit parameters, which is very bad. I don't know if this has changed or if there's a bug report.
agwa wrote:
> Last I looked nginx used fixed 1024 bit parameters, which is very bad.
> I don't know if this has changed or if there's a bug report.
NGINX has had the ssl_dhparam directive (allowing dhparam of arbitrary size) since version 0.7.2, released in 2008.