Description
RSA, DSA, or DH keys that are too small may not withstand modern attacks.
Potential impact
- Ciphertext decryption, signature forgery, or weaker secure channels may result.
Remediation
Choose key sizes for the required security strength and lifetime. Use at least 2048 bits for RSA and finite-field DH, increasing the size when a higher security strength is required. FIPS 186-5 permits DSA only to verify existing signatures, so do not select it for new signature generation.
Examples
Before
c
RSA_generate_key_ex(rsa, 1024, e, NULL);
After
c
RSA_generate_key_ex(rsa, 3072, e, NULL);
Explanation:
- Before: A 1024-bit RSA key is generated.
- After: The RSA key size is increased to 3072 bits. Production code must also check the key-generation return value.