You're probably right. We've already changed to 2048 DH everywhere. Do you have any opinion on if that is a strong enough default?
[1] http://www.openssl.org/docs/apps/ecparam.html
[2] https://github.com/polarssl/polarssl/commit/577e006c2fe4a361...