How to configure RSA key size less than 2048 bits ?
Environment
- Red Hat Enterprise Linux 8.x
Issue
- How to configure crypto policy RSA key size to 1024 ?
Resolution
-
Standard
DEFAULTcrypto policy requires 2048 key size.LEGACY DEFAULT FIPS FUTURE RSA min.1024-bit min.2048-bit min.2048-bit MIN.3072 bit -
In the
DEFAULTmode the RSA keys are accepted if they are at least 2048 bits long. -
If application requires 1024 key size then must need to break the policy and create the custom pmod file as example below.
[root@localhost ~]# cat /etc/crypto-policies/policies/modules/RSA1024.pmod min_rsa_size = 1024 -
If the custom policy should only allow less than 2048 RSA bit keys for Openssh then below entry should be added :
[root@localhost ~]# cat /etc/crypto-policies/policies/modules/RSA1024.pmod min_rsa_size@openssh = 1024 -
Apply the custom policy :
[root@localhost ~]# update-crypto-policies --show DEFAULT [root@localhost ~]# update-crypto-policies --set DEFAULT:RSA1024 Setting system policy to DEFAULT:RSA1024 Note: System-wide crypto policies are applied on application start-up. It is recommended to restart the system for the change of policies to fully take place. [root@localhost ~]# shutdown -r now (log in again after a while) [root@localhost ~]# update-crypto-policies --show DEFAULT:RSA1024
Note: It is recommended to update your application to accept 2048 size because 1024 keys size is no longer considered secure due to vulnerabilities.
This solution is part of Red Hat’s fast-track publication program, providing a huge library of solutions that Red Hat engineers have created while supporting our customers. To give you the knowledge you need the instant it becomes available, these articles may be presented in a raw and unedited form.
Comments