Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's an openssl configuration option, so it does affect performance for Apache with mod_ssl. It's not specific to nginx.

If you do not allow DH ciphers, you'll probably just lose users who deliberately configure their software to use only strong ciphers.

What you can do is put DH ciphers at the end of the list. That way, weaker ciphers are preferred but you're still supporting strong ciphers.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: