aszlig 78b4b90d6c
Merge pull request #39526 (improve dhparams)
This introduces an option that allows us to turn off stateful generation
of Diffie-Hellman parameters, which in some way is still "stateful" as
the generated DH params file is non-deterministic.

However what we can avoid with this is to have an increased surface for
failures during system startup, because generation of the parameters is
done during build-time.

Aside from adding a NixOS VM test it also restructures the type of the
security.dhparams.params option, so that it's a submodule.

A new defaultBitSize option is also there to allow users to set a
system-wide default.

I added a release notes entry that described what has changed and also
included a few notes for module developers using this module, as the
first usage already popped up in NixOS/nixpkgs#39507.

Thanks to @Ekleog and @abbradar for reviewing.
2018-05-08 02:09:46 +02:00
..
2018-03-30 17:33:45 -04:00
2018-03-19 13:12:47 +01:00
2018-03-01 11:47:13 +00:00
2018-04-13 10:30:22 +02:00
2018-04-12 01:35:14 +02:00
2018-03-12 23:37:29 +01:00
2018-04-07 15:06:51 +02:00
2018-03-25 18:29:21 +03:00
2018-04-04 18:26:41 +03:00
2018-04-30 16:49:38 +02:00
2018-03-21 15:33:58 +01:00
2018-03-18 19:15:56 +00:00