Description
RSA keys that are too short lack the security margin needed for long-term confidentiality and signature protection. A 1024-bit RSA key is not considered strong enough for a new system. This does not mean every 1024-bit key can be recovered quickly; attack cost depends on key size, usage and the attacker's resources.
Potential impact
- Recovery of the private key may enable decryption of data protected by that key or signature forgery.
- Stored ciphertext and trust relationships may remain exposed beyond the key's security lifetime.
- Compatibility settings that permit short keys may fail to meet the organization's cryptographic policy.
Remediation
- Generate new RSA keys with at least 2048 bits, and consider 3072 bits or more according to the protection period and security requirements.
- Enforce a minimum length in key generation and check library and service requirements.
- Replace existing short keys after checking certificate, verifier and ciphertext dependencies. Do not delete keys needed to decrypt existing data without a migration plan.
- Review legacy compatibility settings that permit 1024-bit keys.
Examples
Before
go
package main
import (
"crypto/rand"
"crypto/rsa"
"log"
)
// Before: generate a 1024-bit RSA key
func generateWeakRSAKey() *rsa.PrivateKey {
// 1024 bits is insufficient for a new security design
keySize := 1024
priv, err := rsa.GenerateKey(rand.Reader, keySize)
if err != nil {
log.Fatalf("failed to generate RSA key: %v", err)
}
return priv
}
func main() {
_ = generateWeakRSAKey()
}
After
go
package main
import (
"crypto/rand"
"crypto/rsa"
"log"
)
const (
// Recommended minimum: 2048 bits
MinRSAKeySize = 2048
)
// After: generate an RSA key of at least 2048 bits
func generateStrongRSAKey() *rsa.PrivateKey {
keySize := MinRSAKeySize
priv, err := rsa.GenerateKey(rand.Reader, keySize)
if err != nil {
log.Fatalf("failed to generate RSA key: %v", err)
}
return priv
}
func main() {
_ = generateStrongRSAKey()
}
Explanation:
- Before:
generateWeakRSAKeygenerates a 1024-bit key, which does not provide enough security margin for a new security design. - After:
MinRSAKeySizeis fixed at 2048. Random generation, private-key storage and appropriate signature or encryption schemes still require separate care.