Description
RSA keys shorter than 2048 bits may not meet modern service requirements for certificate key strength. Shorter keys provide less resistance to attack; merely having a certificate does not ensure sufficient cryptographic strength.
2048 bits equals 256 bytes. Do not apply this size threshold directly to other algorithms such as ECDSA. ACM import support and the algorithms and key sizes supported by the target service and clients are separate checks.
Potential impact
- A weak certificate key can reduce authentication strength.
- The certificate may not meet organizational cryptographic requirements or client expectations.
Remediation
For RSA, generate a new key of at least 2048 bits, or a stronger size required by your organization, and obtain its matching certificate. Check the certificate/private-key match and service and client support before replacement. Review validity, the trust chain and TLS policy as well.
Examples
These excerpts import RSA certificate files through the older aws_acm module. Supply the matching private key for each certificate. File names do not establish key size; inspect the actual PEM contents.
Before
- name: upload a self-signed certificate
community.aws.aws_acm:
certificate: "{{ lookup('file', 'rsa1024.pem') }}"
private_key: "{{ lookup('file', 'rsa1024-key.pem') }}"
name_tag: my_cert
This illustrates a 1024-bit RSA certificate. Verify the actual file’s key size and do not use it where a stronger key is required.
After
- name: upload a self-signed certificate
community.aws.aws_acm:
certificate: "{{ lookup('file', 'rsa4096.pem') }}"
private_key: "{{ lookup('file', 'rsa4096-key.pem') }}"
name_tag: my_cert
This illustrates a 4096-bit RSA certificate. Confirm support in the associated service; key size does not replace domain or trust-chain validation.