HomeClusterLabs Projects

Feature: libcrmcommon: allow configurable bounds for DH prime length

Description

Feature: libcrmcommon: allow configurable bounds for DH prime length

In a TLS session, the server chooses the prime number used in Diffie-Hellman
parameters, and the client may impose a minimum and maximum bit length of this
prime. New environment variables PCMK_dh_min_bits and PCMK_dh_max_bits allow
the user some control over these values.

Details

Provenance
kgaillotAuthored on Sep 6 2018, 2:25 PM
Parents
rP90e626d73b9b: Log: CIB,executor: improve remote server-side messages
Branches
Unknown
Tags
Unknown

Event Timeline