生成DH證書

Diffie Hellman parameters still calculating after 24 hours

生成命令需要添加 -dsaparam 選項(xiàng)

openssl dhparam -dsaparam -out dhparam.pem 4096

This option instructs OpenSSL to produce "DSA-like" DH parameters (p is such that p-1 is a multiple of a smaller prime q, and the generator has multiplicative order q). This is considerably faster because it does not need to nest the primality tests, and thus only thousands, not millions, of candidates will be generated and tested.
As far as academics know, DSA-like parameters for DH are equally secure; there is no actual advantage to using "strong primes" (the terminology is traditional and does not actually imply some extra strength).
Similarly, you may also use a 2048-bit modulus, which is already very far into the "cannot break it zone". The 4096-bit modulus will make DH computations slower (which is not a real problem for a VPN; these occur only at the start of the connection), but won't actually improve security.
To some extent, a 4096-bit modulus may woo auditors, but auditors are unlikely to be much impressed by a Raspberry-Pi, which is way too cheap anyway.

最后編輯于
?著作權(quán)歸作者所有,轉(zhuǎn)載或內(nèi)容合作請(qǐng)聯(lián)系作者
平臺(tái)聲明:文章內(nèi)容(如有圖片或視頻亦包括在內(nèi))由作者上傳并發(fā)布,文章內(nèi)容僅代表作者本人觀點(diǎn),簡(jiǎn)書系信息發(fā)布平臺(tái),僅提供信息存儲(chǔ)服務(wù)。

推薦閱讀更多精彩內(nèi)容

  • **2014真題Directions:Read the following text. Choose the be...
    又是夜半驚坐起閱讀 9,941評(píng)論 0 23
  • 玫瑰二十五歲了,單身,小美不妖。 玫瑰之所以叫玫瑰,是因?yàn)榘謰尳o的大名叫羅思,取英文名字的時(shí)候,老師說(shuō)你干脆叫ro...
    嶼然閱讀 262評(píng)論 0 0
  • 世界并非是不完美的,或是正處在一條緩慢通向完美的路上;不,它在每一個(gè)瞬間都是完美的,一切罪孽本身就已經(jīng)蘊(yùn)含...
    閑度閱讀 493評(píng)論 2 0
  • 在感情世界中,最多的就是一廂情愿。我們都以為,只要我們做得足夠好,對(duì)方就一定會(huì)被感動(dòng)到。但是,最后被感動(dòng)的只有自己...
    虹妖閱讀 352評(píng)論 2 2
  • 周日上午,去菜場(chǎng)回來(lái)路上,停下來(lái)畫了一棵樹。倒不全是想把這棵樹畫成怎樣美,更主要的是一種形式,我就要在路邊畫點(diǎn)什么...
    沙地人閱讀 769評(píng)論 8 13