Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use RFC 7919 DH parameters #42

Merged
merged 1 commit into from
Mar 19, 2024
Merged

Use RFC 7919 DH parameters #42

merged 1 commit into from
Mar 19, 2024

Conversation

LukasGasior1
Copy link

@LukasGasior1 LukasGasior1 commented Feb 21, 2024

This PR updates the default nginx configuration to use a standard ffdhe2048 group defined in RFC 7919 for its ssl_dhparam. This removes the need to generate the parameters locally (see radixdlt/babylon-nodecli#111), while still allowing to use DHE. RFC 7919 is widely used, e.g. by Mozilla.

This must be added manually because nginx doesn't provide defaults for ssl_dhparam.

8W5vUsMWTfT7eTDp5OWIV7asfV9C1p9tGHdjzx1VA0AEh/VbpX4xzHpxNciG77Qx
iu1qHgEtnmgyqQdgCpGBMMRtx3j5ca0AOAkpmaMzy4t6Gh25PXFAADwqTs6p+Y0K
zAqCkc3OyX3Pjsm1Wn+IpGtNtahR9EGC4caKAH5eZV9q//////////8CAQI=
-----END DH PARAMETERS-----
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link

Docker tags
docker.io/radixdlt/private-babylon-nginx:feature-rfc-7919-dh-params
docker.io/radixdlt/private-babylon-nginx:development-latest

@shambupujar shambupujar merged commit b7f78de into main Mar 19, 2024
5 checks passed
@shambupujar shambupujar deleted the feature/rfc-7919-dh-params branch March 19, 2024 13:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

4 participants