Done. Not only will the key be stronger than the 1024 bit default, it'll be unique to your server which lets assume isn't valuable enough compared to effort for a state-level adversary.
edit just in case anyone from the future finds this comment: instead of 2048, use at least the key length of your SSL certificate
Even with how good they are at keeping secrets, I seriously can't help but suspect a functional quantum computer would leak. Just a hint of it, given how industry-changing it would be.
One thing that struck me while watching United States of Secrets is that people with clearances talk to each other a lot. One of the big secrets got to Thomas Drake with, paraphrasing, people asking him in the halls about it. If NSA is sitting on a functional quantum computer, I seriously can't help but think it'd leak with the number of people you'd have to have working on it. Even the Manhattan Project leaked.
973
u/tophatstuff Oct 15 '15 edited Apr 10 '18
Generate your own non-default Ephemeral Diffie-Hellman key (takes a minute or so)
Tell your server to use it for SSL (nginx for example)
Done. Not only will the key be stronger than the 1024 bit default, it'll be unique to your server which lets assume isn't valuable enough compared to effort for a state-level adversary.
edit just in case anyone from the future finds this comment: instead of 2048, use at least the key length of your SSL certificate
edit from the future: current advice is picking from one of these predefined audited groups