Review RSA certificate key strength

Use an RSA key size that meets the service and organization’s security requirements.

Description

RSA keys shorter than 2048 bits may not meet modern service requirements for certificate key strength. Shorter keys provide less resistance to attack; merely having a certificate does not ensure sufficient cryptographic strength.

2048 bits equals 256 bytes. Do not apply this size threshold directly to other algorithms such as ECDSA. ACM import support and the algorithms and key sizes supported by the target service and clients are separate checks.

Potential impact

  • A weak certificate key can reduce authentication strength.
  • The certificate may not meet organizational cryptographic requirements or client expectations.

Remediation

For RSA, generate a new key of at least 2048 bits, or a stronger size required by your organization, and obtain its matching certificate. Check the certificate/private-key match and service and client support before replacement. Review validity, the trust chain and TLS policy as well.

Examples

These excerpts import RSA certificate files through the older aws_acm module. Supply the matching private key for each certificate. File names do not establish key size; inspect the actual PEM contents.

Before

yaml
- name: upload a self-signed certificate
  community.aws.aws_acm:
    certificate: "{{ lookup('file', 'rsa1024.pem') }}"
    private_key: "{{ lookup('file', 'rsa1024-key.pem') }}"
    name_tag: my_cert

This illustrates a 1024-bit RSA certificate. Verify the actual file’s key size and do not use it where a stronger key is required.

After

yaml
- name: upload a self-signed certificate
  community.aws.aws_acm:
    certificate: "{{ lookup('file', 'rsa4096.pem') }}"
    private_key: "{{ lookup('file', 'rsa4096-key.pem') }}"
    name_tag: my_cert

This illustrates a 4096-bit RSA certificate. Confirm support in the associated service; key size does not replace domain or trust-chain validation.

References