Github user shinrich commented on the pull request: https://github.com/apache/trafficserver/pull/630#issuecomment-219440101 The original code does not use the DH_get_2038_256 function. It effectively rolled it's own. I don't think this is a huge concern, Setting your own DH key seems to be a dying approach. Using the ephemeral DH seems to be more popular these days. As long as we do something reasonably sensible, we should be ok. I'll work on adding the configure time check.
--- If your project is set up for it, you can reply to this email and have your reply appear on GitHub as well. If your project does not have this feature enabled and wishes so, or if the feature is enabled but not working, please contact infrastructure at infrastruct...@apache.org or file a JIRA ticket with INFRA. ---