TLS DHE ciphersuites

E719310

TLS DHE ciphersuites are Transport Layer Security cipher suites that use ephemeral finite-field Diffie–Hellman key exchange to provide forward secrecy between communicating parties.

All labels observed (1)

Label Occurrences
TLS DHE ciphersuites canonical 1

How this entity was disambiguated

Statements (49)

Predicate Object
instanceOf TLS cipher suite family ⓘ
cryptographic protocol component ⓘ
canBeConfiguredWith server-preferred cipher suite ordering ⓘ
canUseAuthenticationAlgorithm DSA ⓘ
ECDSA ⓘ
RSA ⓘ
canUseGroupType IETF standardized finite-field DH groups ⓘ
custom finite-field DH groups ⓘ
cipherSuiteNamePrefix TLS_DHE_ ⓘ
contrastsWith TLS ECDHE ciphersuites ⓘ
TLS RSA key exchange ciphersuites ⓘ
definedIn TLS 1.0 specification ⓘ
linked to: TLS 1.0

TLS 1.1 specification ⓘ
linked to: TLS 1.1

TLS 1.2 specification ⓘ
deprecatedStatus discouraged in many modern configurations in favor of ECDHE ⓘ
exampleCipherSuite TLS_DHE_DSS_WITH_AES_128_CBC_SHA ⓘ
TLS_DHE_DSS_WITH_AES_256_CBC_SHA ⓘ
TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA ⓘ
TLS_DHE_RSA_WITH_AES_128_CBC_SHA ⓘ
TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 ⓘ
TLS_DHE_RSA_WITH_AES_256_CBC_SHA ⓘ
TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 ⓘ
hasPerformanceCharacteristic slower than ECDHE at comparable security levels ⓘ
hasSecurityProperty protects past sessions if server private key is compromised ⓘ
keyExchangeGroupType finite-field Diffie–Hellman group ⓘ
keyExchangeType ephemeral ⓘ
mayBeDisabledFor compatibility with TLS 1.3-only configurations ⓘ
performance reasons ⓘ
negotiatedDuring TLS handshake ⓘ
notDefinedIn TLS 1.3 specification ⓘ
linked to: RFC 8446
providesProperty forward secrecy ⓘ
recommendedKeySize at least 2048-bit DH modulus for modern security ⓘ
relatedAttack Logjam attack ⓘ
requiresClientCapability support for ephemeral finite-field Diffie–Hellman ⓘ
requiresParameter Diffie–Hellman group parameters (p,g) ⓘ
requiresServerCapability support for ephemeral finite-field Diffie–Hellman ⓘ
securityDependsOn discrete logarithm problem hardness in chosen finite field ⓘ
stillUsedIn some TLS 1.1 deployments ⓘ
some TLS 1.2 deployments ⓘ
some legacy TLS 1.0 deployments ⓘ
usedInProtocol Datagram Transport Layer Security (DTLS) ⓘ
linked to: DTLS

Transport Layer Security (TLS) ⓘ
linked to: TLS
usesAuthentication certificate-based authentication ⓘ
usesForConfidentiality symmetric encryption algorithms negotiated in the cipher suite ⓘ
usesForIntegrity message authentication codes or AEAD modes negotiated in the cipher suite ⓘ
usesKeyExchangeAlgorithm ephemeral Diffie–Hellman over finite fields (DHE) ⓘ
usesOperation modular exponentiation ⓘ
vulnerableIf Diffie–Hellman parameters are reused insecurely ⓘ
weak or small Diffie–Hellman groups are used ⓘ

How these facts were elicited

Referenced by (1)

Full triples — surface form annotated when it differs from this entity's canonical label.