Per RFC 9325, the TLS_DHE_RSA_WITH_AES (IANA name) family of ciphers are deprecated.
The following ciphers should thus be removed from the default TLS 1.2 cipher list (OpenSSL names):
DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305