Re: new primes in haproxy after logjam

2015-06-04 Thread Willy Tarreau
Hi Shawn, On Thu, Jun 04, 2015 at 03:24:19PM -0600, Shawn Heisey wrote: > On 6/4/2015 9:54 AM, Willy Tarreau wrote: > > I simply used "openssl dhparam " as suggested, and am trusting > > openssl to provide something reasonably safe since this is how every user > > builds their own dhparam when the

Re: new primes in haproxy after logjam

2015-06-04 Thread Willy Tarreau
On Thu, Jun 04, 2015 at 11:29:00PM +0200, Emmanuel Thomé wrote: > On Thu, Jun 04, 2015 at 05:54:51PM +0200, Willy Tarreau wrote: > > I simply used "openssl dhparam " as suggested, and am trusting > > openssl to provide something reasonably safe since this is how every user > > builds their own dhpa

Re: new primes in haproxy after logjam

2015-06-04 Thread Aleksandar Lazic
Hi. Am 04-06-2015 23:29, schrieb Emmanuel Thomé: On Thu, Jun 04, 2015 at 05:54:51PM +0200, Willy Tarreau wrote: I simply used "openssl dhparam " as suggested, and am trusting openssl to provide something reasonably safe since this is how every user builds their own dhparam when they don't wan

Re: new primes in haproxy after logjam

2015-06-04 Thread Emmanuel Thomé
On Thu, Jun 04, 2015 at 05:54:51PM +0200, Willy Tarreau wrote: > I simply used "openssl dhparam " as suggested, and am trusting > openssl to provide something reasonably safe since this is how every user > builds their own dhparam when they don't want to use the initial one. > > I have no idea how

Re: new primes in haproxy after logjam

2015-06-04 Thread Shawn Heisey
On 6/4/2015 9:54 AM, Willy Tarreau wrote: > I simply used "openssl dhparam " as suggested, and am trusting > openssl to provide something reasonably safe since this is how every user > builds their own dhparam when they don't want to use the initial one. I've been trying to read up on this vulnera

Re: new primes in haproxy after logjam

2015-06-04 Thread Willy Tarreau
Hi Emmanuel, On Thu, Jun 04, 2015 at 05:07:42PM +0200, Emmanuel Thomé wrote: > Hi, > > I heard that following logjam (which I'm a coauthor of), haproxy has > changed its default set of primes. > > That's a good start. However you give no information as to *how* you > generated the primes (correc

new primes in haproxy after logjam

2015-06-04 Thread Emmanuel Thomé
Hi, I heard that following logjam (which I'm a coauthor of), haproxy has changed its default set of primes. That's a good start. However you give no information as to *how* you generated the primes (correct me if I'm mistaken -- I just didn't see such a thing in the commit log, but haven't search