diff options
author | Daiki Ueno <ueno@gnu.org> | 2020-06-26 10:21:26 +0200 |
---|---|---|
committer | Daiki Ueno <ueno@gnu.org> | 2020-06-27 12:57:09 +0200 |
commit | 3f4532862bf9140976d970ab14e102cede61d1c7 (patch) | |
tree | e7f66327cb9a9dd1463b24a3446cb673b14a6a1f /doc/credentials/dhparams/rfc5054-1536.pem | |
parent | 481e48f3236be42ff1fcb96f96c4efcbb2b69242 (diff) | |
download | gnutls-3f4532862bf9140976d970ab14e102cede61d1c7.tar.gz |
dhe: check if DH params in SKE match the FIPS approved algorithmstmp-sp800-56ar3
SP800-56A rev. 3 restricts the FIPS compliant clients to use only
approved DH parameters, defined in RFC 7919 and RFC 3526. This adds a
check in the handling of ServerKeyExchange if DHE is negotiated.
Signed-off-by: Daiki Ueno <ueno@gnu.org>
Diffstat (limited to 'doc/credentials/dhparams/rfc5054-1536.pem')
-rw-r--r-- | doc/credentials/dhparams/rfc5054-1536.pem | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/doc/credentials/dhparams/rfc5054-1536.pem b/doc/credentials/dhparams/rfc5054-1536.pem new file mode 100644 index 0000000000..dc2db6b421 --- /dev/null +++ b/doc/credentials/dhparams/rfc5054-1536.pem @@ -0,0 +1,7 @@ +-----BEGIN DH PARAMETERS----- +MIHHAoHBAJ3vPK+5OSd6sfEqhheke7vbpR30maxMgL7uqWFLGcxNX09fVW4ny95R +xqlL5GB6KRVYkDug0PhDgLZVu5oi6NzfAop87Gfw0IE0sci5eYkUm2CeC+O6tj1H +VIOB28Wx/HZOP0tT3Z2hFYv9PiucjPVu3wGVOTSWJ9sv1T0kt8SGZXcuQ31sf4zk +QnNK98y3roN8Jkrjqb64f4ov6bi1KS5aAh//XpFHnoznoowkQsbzFRgPk0maI03P +duP+0TX5uwIBAg== +-----END DH PARAMETERS----- |