diff options
author | djm@openbsd.org <djm@openbsd.org> | 2015-10-17 00:32:22 +0200 |
---|---|---|
committer | Damien Miller <djm@mindrot.org> | 2015-10-17 00:32:47 +0200 |
commit | b56deb847f4a0115a8bf488bf6ee8524658162fd (patch) | |
tree | 67ffc1513a0ad44627aa42d2b72356e61e494457 /dh.h | |
parent | upstream commit (diff) | |
download | openssh-b56deb847f4a0115a8bf488bf6ee8524658162fd.tar.xz openssh-b56deb847f4a0115a8bf488bf6ee8524658162fd.zip |
upstream commit
increase the minimum modulus that we will send or accept in
diffie-hellman-group-exchange to 2048 bits; ok markus@
Upstream-ID: 06dce7a24c17b999a0f5fadfe95de1ed6a1a9b6a
Diffstat (limited to '')
-rw-r--r-- | dh.h | 9 |
1 files changed, 6 insertions, 3 deletions
@@ -1,4 +1,4 @@ -/* $OpenBSD: dh.h,v 1.13 2015/05/27 23:39:18 dtucker Exp $ */ +/* $OpenBSD: dh.h,v 1.14 2015/10/16 22:32:22 djm Exp $ */ /* * Copyright (c) 2000 Niels Provos. All rights reserved. @@ -44,8 +44,11 @@ int dh_pub_is_valid(DH *, BIGNUM *); u_int dh_estimate(int); -/* Min and max values from RFC4419. */ -#define DH_GRP_MIN 1024 +/* + * Max value from RFC4419. + * Miniumum increased in light of DH precomputation attacks. + */ +#define DH_GRP_MIN 2048 #define DH_GRP_MAX 8192 /* |