SSL supports forward secrecy using two algorithms, the standard Diffie-Hellman (DHE) and the adapted version for use with Elliptic Curve cryptography (ECDHE). Why isn‘t everyone using them, then?
Assuming the interest and the knowledge to deploy forward secrecy are there, two obstacles remain: