It is largely accepted that Diffie-Hellman configured with a key share size of 1024 bits or lower is considered weak and that a nation state would have the resources to be able to break the cipher. To combat this, the TLS server must ensure that Diffie-Hellman enforces key share sizes greater than or equal to 2048 bits. Prerequisites

Dec 17, 2019

The Diffie-Hellman key exchange works like mixing colors by exchanging key colors. Let’s assume we have a color. We can create a new color by adding another color to it.

