diff --git a/doc/ircd.conf.example b/doc/ircd.conf.example index d0821b22..e63767c8 100644 --- a/doc/ircd.conf.example +++ b/doc/ircd.conf.example @@ -72,7 +72,9 @@ serverinfo { * However it has been reported that some clients have broken TLS implementations which may * choke on keysizes larger than 2048-bit, so we would recommend using 2048-bit DH parameters * for now if your keys are larger than 2048-bit. - */ + * + * If you do not provide parameters, some TLS backends will fail on DHE- ciphers, + * and some will succeed but use weak, common DH groups! */ ssl_dh_params = "etc/dh.pem"; /* ssld_count: number of ssld processes you want to start, if you diff --git a/doc/reference.conf b/doc/reference.conf index b8e99f83..235a4375 100644 --- a/doc/reference.conf +++ b/doc/reference.conf @@ -154,7 +154,9 @@ serverinfo { /* ssl_private_key: our ssl private key (if not contained in ssl_cert file) */ #ssl_private_key = "etc/ssl.key"; - /* ssl_dh_params: DH parameters, generate with openssl dhparam -out dh.pem 1024 */ + /* ssl_dh_params: DH parameters, generate with openssl dhparam -out dh.pem 2048 */ + /* If you do not provide parameters, some TLS backends will fail on DHE- ciphers, + and some will succeed but use weak, common DH groups! */ ssl_dh_params = "etc/dh.pem"; /* ssl_cipher_list: A list of ciphers, dependent on your TLS backend */