Sitelet https://github.com/nodejs/node/issues/44539
Skip to content

Weak Diffie-Hellman groups provided by crypto module #44539

Description

@davidben

Node exposes various IKE MODP groups. It appears the list was chosen by exporting every group provided by OpenSSL:
https://github.com/nodejs/node/blob/main/src/crypto/crypto_dh.cc#L222-L229
https://nodejs.org/api/crypto.html#class-diffiehellmangroup

However, some of these groups are too small to be used. See RFC 8247, section 2.4:

Group 5 or the 1536-bit MODP Group has been downgraded from MAY in
RFC 4307 to SHOULD NOT. It was specified earlier, but is now
considered to be vulnerable to being broken within the next few years
by a nation-state-level attack, so its security margin is considered
too narrow.

Group 2 or the 1024-bit MODP Group has been downgraded from MUST- in
RFC 4307 to SHOULD NOT. It is known to be weak against sufficiently
funded attackers using commercially available mass-computing
resources, so its security margin is considered too narrow. It is
expected in the near future to be downgraded to MUST NOT.

Group 1 or the 768-bit MODP Group was not mentioned in RFC 4307 and
so its status was MAY. It can be broken within hours using cheap
off-the-shelf hardware. It provides no security whatsoever. It has,
therefore, been downgraded to MUST NOT.

These are all exposed by Node as "modp1", "modp2", and "modp5". The documentation should reflect their status and they should be deprecated and removed, especially modp1.

Activity

  1. mscdex commented on Sep 6, 2022

    @mscdex
    Contributor

    -1 to removing modp2 yet, it's still used by older SSH (2.0) implementations and in some places it's the only exchange algorithm offered.

  2. davidben commented on Sep 6, 2022

    @davidben
    ContributorAuthor

    It seems OpenSSH itself hasn't supported that since 2016:
    https://www.openssh.com/txt/release-7.2

    • ssh(1), sshd(8): increase the minimum modulus size supported for
      diffie-hellman-group-exchange to 2048 bits.
  3. added a commit that references this issue on Sep 6, 2022
  4. mscdex commented on Sep 7, 2022

    @mscdex
    Contributor

    It seems OpenSSH itself hasn't supported that since 2016: https://www.openssh.com/txt/release-7.2

    • ssh(1), sshd(8): increase the minimum modulus size supported for
      diffie-hellman-group-exchange to 2048 bits.

    That's for the group exchange, which is separate from the modp-based algorithms. Specifically, the modp2-based algorithm is called diffie-hellman-group1-sha1, which is still supported by OpenSSH.

  5. added
    cryptoIssues and PRs related to the crypto subsystem.
    on Sep 7, 2022
  6. bnoordhuis commented on Sep 8, 2022

    @bnoordhuis
    Member

    I remember being mildly apprehensive when they were added back in 2012, modp1 in particular. I'm feeling vindicated now.

    What is an acceptable way forward? Remove modp1 and doc-deprecate (or runtime deprecate?) the other two?

    I'm sympathetic to @mscdex's concern w.r.t. ssh but if working on open source has taught me one thing, it's that users never read the documentation.

  7. tniessen commented on Sep 10, 2022

    @tniessen
    Member

    It appears the list was chosen by exporting every group provided by OpenSSL:
    https://github.com/nodejs/node/blob/main/src/crypto/crypto_dh.cc#L222-L229

    FWIW, that's not entirely accurate. I only recently wrote that part of code to replace a large header file that previously explicitly specified all of these groups. In other words, until recently, the MODP implementation in node did not use any constants provided by OpenSSL :)

    What is an acceptable way forward? Remove modp1 and doc-deprecate (or runtime deprecate?) the other two?

    Let's add a documentation-only deprecation for all three groups as a first step, which is not a semver-major change and can thus land and be released quickly: #44588

  8. bnoordhuis commented on Sep 11, 2022

    @bnoordhuis
    Member

    Warning about or outright removing modp1 is not semver-major under the security exception. I don't expect huge ecosystem fallout, there's probably very little software that would be affected.

  9. 17 remaining items

  10. github-actions commented on Jun 25, 2026

    @github-actions
    Contributor

    This issue has been marked as stale due to 210 days of inactivity.
    It will be automatically closed in 30 days if no further activity occurs. If this is still relevant, please leave a comment or update it to keep it open.

  11. added
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Jun 25, 2026
  12. github-actions commented on Jul 26, 2026

    @github-actions
    Contributor

    This issue has been automatically closed after 30 days of inactivity following its stale status (no activity for a total of 120 days).
    If this is still relevant, feel free to reopen it or leave a comment with additional details so we can continue the discussion.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cryptoIssues and PRs related to the crypto subsystem.securityIssues and PRs related to security.staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions