If you do not allow DH ciphers, you'll probably just lose users who deliberately configure their software to use only strong ciphers.
What you can do is put DH ciphers at the end of the list. That way, weaker ciphers are preferred but you're still supporting strong ciphers.
If you do not allow DH ciphers, you'll probably just lose users who deliberately configure their software to use only strong ciphers.
What you can do is put DH ciphers at the end of the list. That way, weaker ciphers are preferred but you're still supporting strong ciphers.