Description
RSA keys shorter than 2048 bits (256 bytes) do not provide adequate cryptographic strength for TLS certificates. This threshold applies to RSA, not directly to key sizes in other algorithms.
Potential impact
A weak key reduces confidence in server authentication and may fail organizational cryptographic requirements.
Remediation
Reissue the certificate with an RSA key of at least 2048 bits and confirm that the target service supports the chosen key size.
Examples
These certificate-body excerpts are for an edge-optimized API Gateway domain. The 4096-bit example assumes an externally issued certificate. Check the actual key size and certificate validity; renaming the file is not enough.
Before
hcl
resource "aws_api_gateway_domain_name" "example" {
certificate_body = file("./rsa1024.pem")
domain_name = "api.example.com"
}
After
hcl
resource "aws_api_gateway_domain_name" "example" {
certificate_body = file("./rsa4096.pem")
domain_name = "api.example.com"
}