TLS certificate has a short RSA key

Use an RSA key of at least 2048 bits supported by the service.

Description

RSA keys shorter than 2048 bits (256 bytes) do not provide adequate cryptographic strength for TLS certificates. This threshold applies to RSA, not directly to key sizes in other algorithms.

Potential impact

A weak key reduces confidence in server authentication and may fail organizational cryptographic requirements.

Remediation

Reissue the certificate with an RSA key of at least 2048 bits and confirm that the target service supports the chosen key size.

Examples

These certificate-body excerpts are for an edge-optimized API Gateway domain. The 4096-bit example assumes an externally issued certificate. Check the actual key size and certificate validity; renaming the file is not enough.

Before

hcl
resource "aws_api_gateway_domain_name" "example" {
  certificate_body = file("./rsa1024.pem")
  domain_name      = "api.example.com"
}

After

hcl
resource "aws_api_gateway_domain_name" "example" {
  certificate_body = file("./rsa4096.pem")
  domain_name      = "api.example.com"
}

References