Here's a quick (no error checking) way to set up DHparams if they are appended to a cert:
BIO *bio = BIO_new_file(path_to_a_file_with_dhparams, "r");
DH *dh = PEM_read_bio_DHparams(bio, NULL, NULL, NULL);
BIO_free(bio);
SSL_CTX_set_tmp_dh(ctx, dh);
DH_free(dh);
Where do the DH parameters come from? You can generate it yourself (1024 bits here): openssl dhparam -rand - 1024
For a completely isolated implementation (requiring no user certificate changes), see function ngx_ssl_dhparam in nginx-1.0.4/src/event/ngx_event_openssl.cI had been checking things out in nginx and noticed that DH was not implemented. One quick email to Igor and he got it done the same day along with getting this into the next version of nginx. Dude is bad ass.
Now if only someone can convince him or provide a patch to add SPDY support to nginx...
If you try to use only DHE-RSA-AES256-SHA without DH being setup, nothing will connect. If you have DHE-RSA-AES256-SHA as an option with others, it will negotiate a non-DH cipher. (e.g. "DHE-RSA-AES256-SHA:!ADH:SHA" -- you can verify the ordering with `openssl ciphers -v DHE-RSA-AES256-SHA:!ADH:SHA`)
Put:
if(getenv("SSL_CIPHER_SUITES"))
SSL_CTX_set_cipher_list(ctx, getenv("SSL_CIPHER_SUITES"));
anywhere after SSL_CTX_new().But don't bother doing it with stud, because (as I sort of predicted) stud already does this: stud -c <ciphersuites>.
I don't understand what Matt is saying by "stud doesn't enable DH at all". Does stud build its own OpenSSL? The system OpenSSL will already support DHE.
stunnel DH code inserted into stud.