openssl/project

Create a proposal for making various minimum/maximum key sizes configurable

Aperta

#809 aperta il 13 ago 2024

 (3 commenti) (0 reazioni) (0 assegnatari) (1 fork)auto 404
help wanted

Metriche repository

Star
 (3 stelle)
Metriche merge PR
 (Metriche PR in attesa)

Descrizione

https://github.com/openssl/openssl/pull/25094 suggested changing the minimum RSA key size from 512 to 1024 bits.

This will break some use cases - most likely testing. On the other hand 1024 bits is not secure sufficiently anyway so eventually only 2048 bit and above keys should be generated. However this would break even more legacy use cases. To allow them but not allow generating insecure keys by default these minimum (and possibly maximum) key sizes should be made configurable.

A proposal for the configuration needs to be created.

Guida contributor