How to configure RSA key size less than 2048 bits ?

Solution Verified - Updated -

Environment

  • Red Hat Enterprise Linux 8.x

Issue

  • How to configure crypto policy RSA key size to 1024 ?

Resolution

  • Standard DEFAULT crypto policy requires 2048 key size.

                 LEGACY         DEFAULT          FIPS            FUTURE
    RSA          min.1024-bit     min.2048-bit    min.2048-bit       MIN.3072 bit
    
  • In the DEFAULT mode the RSA keys are accepted if they are at least 2048 bits long.

  • If application requires 1024 key size then must need to break the policy and create the custom pmod file as example below.

    [root@localhost ~]# cat /etc/crypto-policies/policies/modules/RSA1024.pmod
    min_rsa_size = 1024
    
  • If the custom policy should only allow less than 2048 RSA bit keys for Openssh then below entry should be added :

    [root@localhost ~]# cat /etc/crypto-policies/policies/modules/RSA1024.pmod
    min_rsa_size@openssh = 1024
    
  • Apply the custom policy :

    [root@localhost ~]# update-crypto-policies --show
    DEFAULT
    
    [root@localhost ~]# update-crypto-policies --set DEFAULT:RSA1024
    Setting system policy to DEFAULT:RSA1024
    
    Note: System-wide crypto policies are applied on application start-up.
    It is recommended to restart the system for the change of policies
    to fully take place.
    
    [root@localhost ~]# shutdown -r now
    (log in again after a while)
    [root@localhost ~]# update-crypto-policies --show
    DEFAULT:RSA1024
    

Note: It is recommended to update your application to accept 2048 size because 1024 keys size is no longer considered secure due to vulnerabilities.

This solution is part of Red Hat’s fast-track publication program, providing a huge library of solutions that Red Hat engineers have created while supporting our customers. To give you the knowledge you need the instant it becomes available, these articles may be presented in a raw and unedited form.

Comments