如何生成DHE(Diffie Hellman Ephemeral Parameters)& Forward Secrecy


DHE生成方法

cd /etc/ssl/certs
openssl dhparam -out dhparam.pem 4096

Nginx使用:

ssl_dhparam /etc/ssl/certs/dhparam.pem;

Apache使用:

#apache 2.4.8 /openssl 1.0.2 之后才支持 DHParams
SSLOpenSSLConfCmd DHParameters "/etc/ssl/certs/dhparams.pem"

已生成好的 4096 

https://https66.com/downloads/dhparam.pem
免备案空间专题