Configure the server to use a randomly generated Diffie-Hellman group
search cancel

Configure the server to use a randomly generated Diffie-Hellman group

book

Article ID: 421852

calendar_today

Updated On:

Products

Endpoint Detection and Response

Issue/Introduction

Endpoint Detection and Response (EDR) server is using default prime number as a parameter during the Diffie-Hellman (DH) key exchange.
You want to know if it can be configured to use a randomly generated Diffie-Hellman group.

Resolution

dhgroupconfig command can be used to re-generate new prime number list of selected group.

  • It allows to enable/disable DH groups for Nginx TLS key exchange
  • It can be used to regenerate DH parameters for group even selection is not changed for Nginx TLS key exchange parameter