{"id":3184,"date":"2016-11-11T16:32:17","date_gmt":"2016-11-11T16:32:17","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=3184"},"modified":"2017-06-07T06:26:58","modified_gmt":"2017-06-07T10:26:58","slug":"open-ssl-dots-pluses","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/open-ssl-dots-pluses\/","title":{"rendered":"Those Open SSL Dots and Pluses Mean Something"},"content":{"rendered":"<h2>Making Sense of the way Open SSL generates\u00a0Diffie-Hellman Parameters.<\/h2>\n<p>This one is for the cryptography lovers and the curious\u2026<\/p>\n<p>Diffie-Hellman key exchange, also known as DH or DHE, is one of the less popular key exchange methods used in the SSL\/TLS protocol (you may know the most widely used key exchange method: RSA). Though DH is much more commonly used in the SSH and IPsec protocols.<a href=\"#_ftn1\" name=\"_ftnref1\">[1]<\/a><\/p>\n<p>Key exchange algorithms are designed to allow two different parties to safely create an encryption key that can be used to communicate securely, and do so over an unsecured (or open) network, like the internet.<\/p>\n<p>Every key exchange method uses different math to achieve this. Without getting into the specifics, Diffie-Hellman uses\u00a0 a set of numbers known as \u201cDH parameters\u201d that kick off the whole key exchange process. These parameters include a very large prime number which is pre-computed. This means they are generated by the server before it starts forming connections. Properly supporting Diffie-Hellman requires that you generate unique DH parameters for your server.<\/p>\n<p>If you have used OpenSSL to generate Diffie-Hellman parameters, you may have noticed the console chugging along outputting \u201cdots\u201d(.) and \u201cpluses\u201d (+). Generating these parameters takes some time, so showing some sort of indicator that your server is still running is helpful. But these symbols are more than just a primitive \u201cloading bar.\u201d<\/p>\n<figure id=\"attachment_3185\" aria-describedby=\"caption-attachment-3185\" style=\"width: 975px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-3185 size-full\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/11\/DHE.png\" alt=\"open ssl dots pluses\" width=\"975\" height=\"570\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/11\/DHE.png 975w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/11\/DHE-300x175.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/11\/DHE-768x449.png 768w\" sizes=\"auto, (max-width: 975px) 100vw, 975px\" \/><figcaption id=\"caption-attachment-3185\" class=\"wp-caption-text\">When generating Diffie-Hellman parameters in OpenSSL, it outputs a series of \u201c.\u201d and \u201c+\u201d to indicate it is searching for a suitable prime number.<\/figcaption><\/figure>\n<p>The dots and pluses tell you every time your server has generated a number that it thinks may be a \u201csafe prime\u201d which can be used as the cryptographic underpinning for Diffie-Hellman SSL\/TLS connections.<\/p>\n<p>Each dot represents a generated number that might be a prime, and each plus represents a number that was tested and found not to be a prime. Proving large numbers are prime is a rather intensive task, so a mathematical shortcut (the <a href=\"https:\/\/en.wikipedia.org\/wiki\/Miller%E2%80%93Rabin_primality_test\" rel=\"nofollow\">Miller-Rabin primality test<\/a>) is used to more quickly estimate if a number if prime. While it is not a 100% guarantee, it gets nearly as close with a lot less effort.<\/p>\n<p>There is a third symbol as well: an asterisk (*). This indicates that a safe prime was found. You will only see the asterisk at the end of the output when your server has found the suitable prime it will use for your Diffie-Hellman parameters.<\/p>\n<p>You will see in the screenshot above, that the output from generating DH parameters will end with sets of \u201c++*\u201d Planetbeing, a user over at StackExchange, <a href=\"https:\/\/security.stackexchange.com\/a\/140639\/56670\" rel=\"nofollow\">explained why<\/a> that is. They wrote, \u201cThe first + means the prime p itself has passed one iteration of the Miller-Rabin primality test. The second + means the (p-1)\/2 also has passed one iteration of the Miller-Rabin primality test. The first * indicates both p and (p-1)\/2 has passed an iteration of the Miller-Rabin primality test.\u201d<\/p>\n<p>This process is then repeated because OpenSSL wants to be very sure that this number is likely a prime, and therefore safe. The number of times this is repeated <a href=\"https:\/\/github.com\/openssl\/openssl\/blob\/6f0ac0e2f27d9240516edb9a23b7863e7ad02898\/include\/openssl\/bn.h#L129\" rel=\"nofollow\">depends on the bit-size of the parameters<\/a>.<\/p>\n<p>I generated 4096-bit parameters on a standard VPS to see how many dots and pluses would be outputted and how long it would take. It took just over 20 minutes and generated 26090 dots and 164 pluses, before finally finding a suitable prime.<\/p>\n<p>April King, an engineer at Mozilla, recently generated a truly massive 32kb Diffie-Hellman group for <a href=\"https:\/\/badssl.com\/\" rel=\"nofollow\">badssl.com<\/a>, a test-bed website for different SSL errors. It took <a href=\"https:\/\/twitter.com\/aprilmpls\/status\/796048345693388800\" rel=\"nofollow\">nearly 20 days<\/a> and generated one million numbers in search for a suitable prime of that size!<\/p>\n<p>The way Diffie-Hellman is implemented in most server OSs makes it <a href=\"https:\/\/weakdh.org\/\" rel=\"nofollow\">a security vulnerability<\/a>, and browsers like Chrome have <a href=\"https:\/\/www.thesslstore.com\/blog\/tracking-ssl-changes-chrome-53\/\">recently removed support for these ciphers<\/a>, so we are likely to see less and less of it. Diffie-Hellman exists in other forms that are still safe to use, such as ECDHE, which incorporates Elliptic Curve Cryptography.<\/p>\n<hr \/>\n<p><a href=\"#_ftnref1\" name=\"_ftn1\">[1]<\/a> <a href=\"https:\/\/weakdh.org\/imperfect-forward-secrecy-ccs15.pdf\" rel=\"nofollow\">https:\/\/weakdh.org\/imperfect-forward-secrecy-ccs15.pdf<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Making Sense of the way Open SSL generates\u00a0Diffie-Hellman Parameters. This one is for the cryptography lovers and the curious\u2026 Diffie-Hellman key exchange, also known as DH or DHE, is one&#8230;<\/p>\n","protected":false},"author":2,"featured_media":3186,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[260,261,259,262,136,161],"class_list":["post-3184","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","tag-diffie-helman","tag-dots","tag-open-ssl","tag-pluses","tag-ssl","tag-tls","post-with-tags"],"views":12357,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/11\/Depositphotos_10694670_m-2015.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3184","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=3184"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3184\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/3186"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=3184"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=3184"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=3184"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}