Why are DHE cipher suites disabled?

  • Cryptographically speaking they are quite secure when the DH params are properly configured.

    Firefox and Chrome handle this fine by punting an "weak ephemeral Diffie-Hellman key" error.

    If you're concerned with interfering with the user's experience you can handle it the same way you fallback with RC4.


