openssl L<openssl-dhparam(1)> application. This application
guarantees that "strong" primes are used.
-Files dh2048.pem, and dh4096.pem in the 'apps' directory of the current
-version of the OpenSSL distribution contain two of the MODP Diffie-Hellman
-groups for IKE as per RFC 3526. These files can be converted into C code
-using the B<-C> option of the L<openssl-dhparam(1)> application. Generation
-of custom DH parameters during installation should still be preferred to
-stop an attacker from specializing on a commonly used group. File dh1024.pem
-contains old parameters that must not be used by applications.
-
An application may either directly specify the DH parameters or
can supply the DH parameters via a callback function.