Update hardcoded DH parameters to IANA standards

The source defining the current fallback and hardcoded DH parameters
has disappeared from the web a long time ago, and RFC 3526 defines the
most current Diffie-Hellman MODP groups, so update to those new values.

Author: Daniel Gustafsson
Reviewed-by: Peter Eisentraut, Michael Paquier
Discussion: https://postgr.es/m/5E60AC9A-CB10-4851-9EF2-7209490A164C@yesql.se
This commit is contained in:
Michael Paquier 2019-07-05 10:47:32 +09:00
parent 08aa131c7a
commit 8a810a177c
1 changed files with 11 additions and 10 deletions

View File

@ -206,19 +206,20 @@ typedef struct Port
* Hardcoded DH parameters, used in ephemeral DH keying. (See also * Hardcoded DH parameters, used in ephemeral DH keying. (See also
* README.SSL for more details on EDH.) * README.SSL for more details on EDH.)
* *
* If you want to create your own hardcoded DH parameters * This is the 2048-bit DH parameter from RFC 3526. The generation of the
* for fun and profit, review "Assigned Number for SKIP * prime is specified in RFC 2412 Appendix E, which also discusses the
* Protocols" (http://www.skip-vpn.org/spec/numbers.html) * design choice of the generator. Note that when loaded with OpenSSL
* for suggestions. * this causes DH_check() to fail on DH_NOT_SUITABLE_GENERATOR, where
* leaking a bit is preferred.
*/ */
#define FILE_DH2048 \ #define FILE_DH2048 \
"-----BEGIN DH PARAMETERS-----\n\ "-----BEGIN DH PARAMETERS-----\n\
MIIBCAKCAQEA9kJXtwh/CBdyorrWqULzBej5UxE5T7bxbrlLOCDaAadWoxTpj0BV\n\ MIIBCAKCAQEA///////////JD9qiIWjCNMTGYouA3BzRKQJOCIpnzHQCC76mOxOb\n\
89AHxstDqZSt90xkhkn4DIO9ZekX1KHTUPj1WV/cdlJPPT2N286Z4VeSWc39uK50\n\ IlFKCHmONATd75UZs806QxswKwpt8l8UN0/hNW1tUcJF5IW1dmJefsb0TELppjft\n\
T8X8dryDxUcwYc58yWb/Ffm7/ZFexwGq01uejaClcjrUGvC/RgBYK+X0iP1YTknb\n\ awv/XLb0Brft7jhr+1qJn6WunyQRfEsf5kkoZlHs5Fs9wgB8uKFjvwWY2kg2HFXT\n\
zSC0neSRBzZrM2w4DUUdD3yIsxx8Wy2O9vPJI8BD8KVbGI2Ou1WMuF040zT9fBdX\n\ mmkWP6j9JM9fg2VdI9yjrZYcYvNWIIVSu57VKQdwlpZtZww1Tkq8mATxdGwIyhgh\n\
Q6MdGGzeMyEstSr/POGxKUAYEY18hKcKctaGxAMZyAcpesqVDNmWn6vQClCbAkbT\n\ fDKQXkYuNs474553LBgOhgObJ4Oi7Aeij7XFXfBvTFLJ3ivL9pVYFxg5lUl86pVq\n\
CD1mpF1Bn5x8vYlLIhkmuquiXsNV6TILOwIBAg==\n\ 5RXSJhiY+gUQFXKOWoqsqmj//////////wIBAg==\n\
-----END DH PARAMETERS-----\n" -----END DH PARAMETERS-----\n"
/* /*