[jetty-users] how to properly deployDiffie-Hellman on my server


Please guide on how to properly deploy Diffie-Hellman on my server. I am using Jetty 9.2.9 with jdk1.7.


This is my current configuration in jetty-ssl.xml but SSL scan report shows that “This server supports insecure Diffie-Hellman (DH) key exchange parameters (Logjam)”


<Set name="ExcludeCipherSuites">

    <Array type="String">








 <!-- Enable Forward Secrecy Ciphers.       Note: this replaces the default Include Cipher list -->

  <Set name="IncludeCipherSuites">

    <Array type="String">





<!-- Eliminate Insecure Protocols -->

  <Call name="addExcludeProtocols">


     <Array type="java.lang.String">













