[squid-users] Squid 3.5 Forward Secrecy on https_port

But does this mean that ECDHE isn't supported by Squid?

I had a related question as the original poster. Some U.S. federal security
standards (e.g. NSA Suite B) require ECDH and ECDHE adds perfect forward

Can squid bump TLS 1.2 traffic that uses ECDHE and that use certificates
signed using ECDSA?

>> Does anyone see something missing in my https_port configuration that
>> is causing it to not use the ECDHE keys?
> I made some updates above, the dh.params file wasn't being found, changed
that line to use full path, and its now use DHE ciphers, but not ECDHE

ECDHE is not considered safe by a group of cryptologists since the EC
implementation is based on secret parameters that only the author of the
algorithm has.
See also http://safecurves.cr.yp.to/rigid.html

