3 ms·
... but clients can guard against weak server-side DHE by rejecting DHE ciphersuites. So I think the GP was correct that this diagnostic should be updated.
by rtb 11y ago
... but clients can guard against weak server-side DHE by rejecting DHE ciphersuites. So I think the GP was correct that this diagnostic should be updated.
- mynameisvlad 11y agoNo, because as agwa pointed out, howsmyssl checks client security. There's nothing wrong with a DHE cipher suite and it can be used in a secure manner quite easily. Since this is wholly on the server, and howsmyssl has no way of testing a server you're connecting to, then there's no possible way for it to know if your specific connections are okay or not. Based solely on the client suites tested, DHE would still be considered secure. It's only the interaction with an insecure server that makes it insecure.
- kpcyrd 11y agoweakdh can be mitigated client side. The website[0] itself has a test for it, which works by requesting this file[1]. [0]: https://weakdh.org/ https://weakdh.org/ [1]: https://dhe512.zmap.io/dhe512test.js https://dhe512.zmap.io/dhe512test.js