Set minimum DH group size to 1024 bits.

DH groups less than 1024 bits are clearly not very safe. Ideally servers
would switch to ECDHE because 1024 isn't great either, but this will
serve for the short term.


Change-Id: Ic9aac714cdcdcbfae319b5eb1410675d3b903a69
Reviewed-by: David Benjamin <>
Reviewed-by: Adam Langley <>
diff --git a/ssl/test/runner/common.go b/ssl/test/runner/common.go
index 2e6ddf3..e1479e9 100644
--- a/ssl/test/runner/common.go
+++ b/ssl/test/runner/common.go
@@ -707,6 +707,10 @@
 	// BadFinished, if true, causes the Finished hash to be broken.
 	BadFinished bool
+	// DHGroupPrime, if not nil, is used to define the (finite field)
+	// Diffie-Hellman group. The generator used is always two.
+	DHGroupPrime *big.Int
 func (c *Config) serverInit() {