Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-8352

Increase Diffie-Helman modulus to 2048-bits

    Details

    • Type: Task
    • Status: Closed
    • Priority: Critical
    • Resolution: Fixed
    • Fix Version/s: 10.0.21, 5.5.45
    • Component/s: SSL
    • Labels:
      None
    • Sprint:
      5.5.45

      Description

      Debian reported a bug in an older version of MariaDB relating to using a 512-bit modulus when
      negotiating a Finite-Field Diffie-Hellman Ephemeral (FFDHE) handshake in TLS.

      This was increased to 1024 in 10.0.18, but MySQL increased this to 2048 in their 5.7.7 release in Oct 2014, and the current consensus is that, while 1024 is currently sufficient, it's unlikely to be in the near to medium future.

      Debian bug report: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=788905

        Gliffy Diagrams

          Attachments

            Issue Links

              Activity

              There are no comments yet on this issue.

                People

                • Assignee:
                  serg Sergei Golubchik
                  Reporter:
                  greenman Ian Gilfillan
                • Votes:
                  0 Vote for this issue
                  Watchers:
                  3 Start watching this issue

                  Dates

                  • Created:
                    Updated:
                    Resolved:

                    Time Tracking

                    Estimated:
                    Original Estimate - Not Specified
                    Not Specified
                    Remaining:
                    Remaining Estimate - 0 minutes
                    0m
                    Logged:
                    Time Spent - 5 minutes
                    5m

                      Agile