openssl/project

Create a proposal for making various minimum/maximum key sizes configurable

Open

#809 opened on Aug 13, 2024

View on GitHub
 (3 comments) (0 reactions) (0 assignees) (1 fork)auto 404
help wanted

Repository metrics

Stars
 (3 stars)
PR merge metrics
 (PR metrics pending)

Description

https://github.com/openssl/openssl/pull/25094 suggested changing the minimum RSA key size from 512 to 1024 bits.

This will break some use cases - most likely testing. On the other hand 1024 bits is not secure sufficiently anyway so eventually only 2048 bit and above keys should be generated. However this would break even more legacy use cases. To allow them but not allow generating insecure keys by default these minimum (and possibly maximum) key sizes should be made configurable.

A proposal for the configuration needs to be created.

Contributor guide