A further workaround solution could be switching to DH group 31 when using OpenSSL flavor. Prerequisite is that the other endpoint must support this group.
I'll test this with my configuration next week.
I'll test this with my configuration next week.
"