Which Diffie Hellman Group?

Which Diffie Hellman Group?

dh-group —Diffie-Hellman group for key establishment.
  • group1 —768-bit Modular Exponential (MODP) algorithm.
  • group2 —1024-bit MODP algorithm.
  • group5 —1536-bit MODP algorithm.
  • group14 —2048-bit MODP group.
  • group15 —3072-bit MODP algorithm.
  • group16 —4096-bit MODP algorithm.

What Diffie-Hellman DH group should I use?

Guidelines: If you are using encryption or authentication algorithms with a 128-bit key, use Diffie-Hellman groups 5, 14, 19, 20 or 24. If you are using encryption or authentication algorithms with a 256-bit key or higher, use Diffie-Hellman group 21.

How do I choose a Diffie-Hellman group?

Deciding Which Diffie-Hellman Modulus Group to Use

A larger modulus provides higher security but requires more processing time. You must have a matching modulus group on both peers. If you select AES encryption, to support the large key sizes required by AES, you should use Diffie-Hellman (DH) Group 5 or higher.

Robert Thorne
Author

Robert Thorne

Robert Thorne covers electric vehicle innovations, autonomous driving systems, global mobility trends, and automotive engineering developments.