Skip to content
Draft
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions src/lib-ssl-iostream/iostream-openssl-params.c
Original file line number Diff line number Diff line change
Expand Up @@ -45,8 +45,17 @@ int openssl_iostream_generate_params(buffer_t *output, unsigned int dh_length,
const char **error_r)
{
if (generate_dh_parameters(512, output, error_r) < 0)
unsigned int minimal_dh_size = 512;
#ifdef OPENSSL_FIPS
if (FIPS_mode() > 0) {
minimal_dh_size = 2048;
i_warning("FIPS mode detected. Setting minimum DH params size from 512 to 2048. Accepting SSL connections after first start might take longer.");
};
#endif
if (generate_dh_parameters(minimal_dh_size, output, error_r) < 0)
return -1;
if (dh_length != 512) {
if (dh_length > minimal_dh_size) {
if (generate_dh_parameters(dh_length, output, error_r) < 0)
return -1;
}
Expand Down