On 12-Sep-2013, at 1:18, Florian Weimer <fw at deneb.enyo.de> wrote: > I suppose the simplest mitigation would be to avoid ephemeral > Diffie-Hellman key agreement altogether, that is, remove it from the > cipher suite default. By the way this ticket is a dup of #676563 --srs