I would argue that 1024 DHE is worse than no PFS, for the same reason
that using DES is a bad move. It is likely to be inherently insecure and
provides a higher sense of security than is valid for the situation. By
insisting that 1024 to be ok, you are, in theory, permitting people to
feel comfortable with an insecure system.

I have always approached that no encryption is better than bad
encryption, otherwise the end user will feel more secure than they
should and is more likely to share information or data they should not
be on that line.

By insisting on 2048 (or higher), you force the issue and ensure that
the overall network is more secure.

