From 6de1fe90860ddfe768864838637f681537f3f108 Mon Sep 17 00:00:00 2001 From: Bernd Edlinger Date: Mon, 22 Jul 2019 22:50:19 +0200 Subject: Enforce a minimum DH modulus size of 512 bits [extended tests] Reviewed-by: Paul Dale (Merged from https://github.com/openssl/openssl/pull/9437) --- CHANGES | 3 +++ 1 file changed, 3 insertions(+) (limited to 'CHANGES') diff --git a/CHANGES b/CHANGES index 3507e350e3..acaa099518 100644 --- a/CHANGES +++ b/CHANGES @@ -9,6 +9,9 @@ Changes between 1.1.1 and 3.0.0 [xx XXX xxxx] + *) Enforce a minimum DH modulus size of 512 bits. + [Bernd Edlinger] + *) Changed DH parameters to generate the order q subgroup instead of 2q. Previously generated DH parameters are still accepted by DH_check but DH_generate_key works around that by clearing bit 0 of the -- cgit v1.2.3