diff options
author | Jeremy Harris <jgh146exb@wizmail.org> | 2021-11-06 20:56:05 +0000 |
---|---|---|
committer | Jeremy Harris <jgh146exb@wizmail.org> | 2021-11-06 20:56:05 +0000 |
commit | 6db92eab5917e515c83fd773dad6111177a0207f (patch) | |
tree | 6dfbeddf2b6fb5ba7bc2726e4752f3d05827aea5 /doc/doc-docbook | |
parent | 96bf6859ea5c042605edd208ff7ce557b73454f2 (diff) |
Revert "GnuTLS: lose DH-param setup, for recent library versions where no longer needed". Bug 2822
It seems the documentation lies and the params really are needed.
This reverts commits 041bf37266, 49132a3bb5c6
Diffstat (limited to 'doc/doc-docbook')
-rw-r--r-- | doc/doc-docbook/spec.xfpt | 7 |
1 files changed, 1 insertions, 6 deletions
diff --git a/doc/doc-docbook/spec.xfpt b/doc/doc-docbook/spec.xfpt index dcda2ff79..a8cd63b19 100644 --- a/doc/doc-docbook/spec.xfpt +++ b/doc/doc-docbook/spec.xfpt @@ -18429,12 +18429,7 @@ larger prime than requested. The value of this option is expanded and indicates the source of DH parameters to be used by Exim. -This option is ignored for GnuTLS version 3.6.0 and later. -The library manages parameter negotiation internally. - -&*Note: The Exim Maintainers strongly recommend, -for other TLS library versions, -using a filename with site-generated +&*Note: The Exim Maintainers strongly recommend using a filename with site-generated local DH parameters*&, which has been supported across all versions of Exim. The other specific constants available are a fallback so that even when "unconfigured", Exim can offer Perfect Forward Secrecy in older ciphersuites in TLS. |