guarantees that "strong" primes are used.
Files dh2048.pem, and dh4096.pem in the 'apps' directory of the current
-version of the OpenSSL distribution contain the 'SKIP' DH parameters,
-which use safe primes and were generated verifiably pseudo-randomly.
-These files can be converted into C code using the B<-C> option of the
-L<openssl-dhparam(1)> application. Generation of custom DH
-parameters during installation should still be preferred to stop an
-attacker from specializing on a commonly used group. File dh1024.pem
+version of the OpenSSL distribution contain two of the MODP Diffie-Hellman
+groups for IKE as per RFC 3526. These files can be converted into C code
+using the B<-C> option of the L<openssl-dhparam(1)> application. Generation
+of custom DH parameters during installation should still be preferred to
+stop an attacker from specializing on a commonly used group. File dh1024.pem
contains old parameters that must not be used by applications.
An application may either directly specify the DH parameters or