Conversation

TIL: if you want TLS downgrade protection, you MUST only use one of the DHE or ECDH key exchange algorithms. Others like DH_RSA do not sign the random bytes in Hello messages used to prevent TLS downgrade attacks.
1
3
Show replies