3 ms·
Yes, they are problematic. Cipher suites are typically tied to a particular key algorithm. Microsoft does support the DHE key exchange, but only in combination
by ivanr 13y ago
Yes, they are problematic. Cipher suites are typically tied to a particular key algorithm. Microsoft does support the DHE key exchange, but only in combination with DSA keys (DSS in the cipher suite string). There are a couple of problems with that. First, if you do use DSA keys, you don't get to use any RSA suites[1], which are much better supported. Just as an illustration Chrome supports only one DSA suite. Second, virtually no one uses DSA keys today for SSL. So, all the advice you will find is about RSA keys. Third, and worst, Microsoft does not actually support DSA keys stronger than 1024 bits, and you can't use 1024-bit keys because they're considered too weak.
I am sure there is a reason, but Microsoft never supported the DHE and RSA combination, which was the only way to achieve Forward Secrecy before ECDHE became widely supported.
[1] Actually, some web servers support multiple keys/certificates. With Apache, for example, you could have an SSL site with RSA, DSA, and ECDSA keys if you wanted. I think nginx is adding this capability too. But IIS does not support it.