Antoine Pitrou <pit...@free.fr> added the comment:

Well the OpenSSL docs say “DH_generate_parameters() may run for several hours 
before finding a suitable prime”, which sounds like a good reason not to do it 
every time your program is run.

Anyway, SSL_CTX_set_tmp_dh() should allow us to set DH parameters on a SSL 
context, PEM_read_DHparams() to read them from a PEM file, and OpenSSL's source 
tree has a couple of PEM files with "strong" DH parameters for various key 
sizes.

----------
stage:  -> needs patch

_______________________________________
Python tracker <rep...@bugs.python.org>
<http://bugs.python.org/issue13626>
_______________________________________
_______________________________________________
Python-bugs-list mailing list
Unsubscribe: 
http://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com

Reply via email to