[openssl-users] Selection of DHE ciphers based on modulus size of DH

Salz, Rich rsalz at akamai.com
Wed Jun 6 23:15:39 UTC 2018

Without commenting on whether or not your understanding is correct (the client gets the params and can see how big the key is, no?), I will point out that the way DHE works is defined by the IETF RFC’s, and they have not changed.

