Skip to content

Commit fcda6cf

Browse files
authored
Merge pull request ruby#674 from rhenium/ky/ssl-update-default-dh-params
ssl: use ffdhe2048 from RFC 7919 as the default DH group parameters
2 parents 8eb0715 + a5527cb commit fcda6cf

File tree

1 file changed

+9
-9
lines changed

1 file changed

+9
-9
lines changed

lib/openssl/ssl.rb

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -34,21 +34,21 @@ class SSLContext
3434
}
3535

3636
if defined?(OpenSSL::PKey::DH)
37-
DEFAULT_2048 = OpenSSL::PKey::DH.new <<-_end_of_pem_
37+
DH_ffdhe2048 = OpenSSL::PKey::DH.new <<-_end_of_pem_
3838
-----BEGIN DH PARAMETERS-----
39-
MIIBCAKCAQEA7E6kBrYiyvmKAMzQ7i8WvwVk9Y/+f8S7sCTN712KkK3cqd1jhJDY
40-
JbrYeNV3kUIKhPxWHhObHKpD1R84UpL+s2b55+iMd6GmL7OYmNIT/FccKhTcveab
41-
VBmZT86BZKYyf45hUF9FOuUM9xPzuK3Vd8oJQvfYMCd7LPC0taAEljQLR4Edf8E6
42-
YoaOffgTf5qxiwkjnlVZQc3whgnEt9FpVMvQ9eknyeGB5KHfayAc3+hUAvI3/Cr3
43-
1bNveX5wInh5GDx1FGhKBZ+s1H+aedudCm7sCgRwv8lKWYGiHzObSma8A86KG+MD
44-
7Lo5JquQ3DlBodj3IDyPrxIv96lvRPFtAwIBAg==
39+
MIIBCAKCAQEA//////////+t+FRYortKmq/cViAnPTzx2LnFg84tNpWp4TZBFGQz
40+
+8yTnc4kmz75fS/jY2MMddj2gbICrsRhetPfHtXV/WVhJDP1H18GbtCFY2VVPe0a
41+
87VXE15/V8k1mE8McODmi3fipona8+/och3xWKE2rec1MKzKT0g6eXq8CrGCsyT7
42+
YdEIqUuyyOP7uWrat2DX9GgdT0Kj3jlN9K5W7edjcrsZCwenyO4KbXCeAvzhzffi
43+
7MA0BM0oNC9hkXL+nOmFg/+OTxIy7vKBg8P+OxtMb61zO7X8vC7CIAXFjvGDfRaD
44+
ssbzSibBsu/6iGtCOGEoXJf//////////wIBAg==
4545
-----END DH PARAMETERS-----
4646
_end_of_pem_
47-
private_constant :DEFAULT_2048
47+
private_constant :DH_ffdhe2048
4848

4949
DEFAULT_TMP_DH_CALLBACK = lambda { |ctx, is_export, keylen| # :nodoc:
5050
warn "using default DH parameters." if $VERBOSE
51-
DEFAULT_2048
51+
DH_ffdhe2048
5252
}
5353
end
5454

0 commit comments

Comments
 (0)