Otherwise, forward secrecy leaves the attacker with the challenge of cracking the key-agreement protocol, which is likely quite computationally intensive, but may be feasible for sessions of sufficiently high value.

Thus forward secrecy places cost constraints on the efficacy of bulk surveillance, recovering all past traffic is generally infeasible, and even recovery of individual sessions may be infeasible given a sufficiently-strong key agreement method.

Thus the configuration parameters related to Elliptic-Curve forward secrecy are available when Postfix is linked with Open SSL ≥ 1.0.0 (provided EC support has not been disabled by the vendor, as in some versions of Red Hat Linux).

The acronym for forward secrecy over prime fields is EDH for Ephemeral Diffie-Hellman (also abbreviated as DHE).Postfix supports forward secrecy of TLS network communication since version 2.2.This support was adopted from Lutz Jänicke's "Postfix TLS patch" for earlier Postfix versions.The acronym for the elliptic curve version is EECDH which is short for Ephemeral Elliptic Curve Diffie-Hellman (also abbreviated as ECDHE).It is not essential to know what these are, but one does need to know that Open SSL supports EECDH with version 1.0.0 or later.

