• Bruce Momjian's avatar
    SSL support for ephemeral DH keys. · 55d05323
    Bruce Momjian authored
    As the comment headers in be-secure.c discusses, EPH preserves
    confidentiality even if the static private key (which is usually
    kept unencrypted) is compromised.
    
    Because of the value of this, common default values are hard-coded
    to protect the confidentiality of the data even if an attacker
    successfully deletes or modifies the external file.
    
    Bear Giles
    55d05323
be-secure.c 15.2 KB