diff --git a/analyze.py b/analyze.py index c886ee8..c1c0d4a 100755 --- a/analyze.py +++ b/analyze.py @@ -217,7 +217,7 @@ def is_intermediate(results): failures[lvl].append("use a certificate signed with %s" % " or ".join(inter["certificate_signatures"])) isinter = False if not has_pfs: - failures[lvl].append("consider using DHE of at least 2048bits and ECC of at least 256bits") + failures[lvl].append("consider using DHE of at least 2048bits and ECC of 256bits and greater") if not has_ocsp: failures[lvl].append("consider enabling OCSP Stapling") if results['serverside'] != 'True': @@ -266,7 +266,7 @@ def is_modern(results): failures[lvl].append("use a certificate signed with %s" % " or ".join(modern["certificate_signatures"])) ismodern = False if not has_pfs: - failures[lvl].append("use DHE of at least 2048bits and ECC of at least 256bits") + failures[lvl].append("use DHE of at least 2048bits and ECC of at 256bits and greater") ismodern = False if not has_ocsp: failures[lvl].append("consider enabling OCSP Stapling")