Hi !
Context
Diffie-Hellman key exchange is known vulnerable to attacks since 2015.
Since dovecot 2.3, DH algorithms are deprecated.
Generating our own DH parameters should be avoided: see mozilla/ssl-config-generator#60.
Instead, we should use a secure group from the rfc7919. Different sizes are available; 2048,3072 or 4096.
Internet.nl recommends to use ffdhe3072 or ffdhe4096.
Regarding docker-mailserver
Benefits
Hi !
Context
Diffie-Hellman key exchange is known vulnerable to attacks since 2015.
Since dovecot 2.3, DH algorithms are deprecated.
Generating our own DH parameters should be avoided: see mozilla/ssl-config-generator#60.
Instead, we should use a secure group from the rfc7919. Different sizes are available; 2048,3072 or 4096.
Internet.nl recommends to use ffdhe3072 or ffdhe4096.
Regarding docker-mailserver
Benefits