RE: PKINIT for gsissh
Ali Gholami <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Message-ID | <[email protected]> |
Hi Douglas, I just got some feedback that Globus community is also intersted to use larger defaul RSA keys and I submited as a bug to be fixed in the new releases. The most obvious reason for using small keys was the overhead with the larger keys. Best Ali ________________________________________ From: Douglas E. Engert [[email protected]] Sent: Tuesday, October 04, 2011 5:43 PM To: [email protected] Subject: Re: PKINIT for gsissh Ali, You may want to post a question about why are 512 bit RSA keys in proxy certificates still being used, and how to use larger keys to: [email protected] On 10/4/2011 10:26 AM, Love Hörnquist Åstrand wrote: > > 4 okt 2011 kl. 15:41 skrev Ali Gholami: > >>> Hi Love, >>> >>>> Well, when I debug it, I see "indata.length = 83" and "sig->data" which I think is the "rsa" size equal to 64. My question was the purpose of this if clause: "if (indata.data != data->data)". >>> >>> you have 512byte rsa keys, todays larger digests (sha512) doesn't fit inside the rsa encryption. >>> >>> While the code should not choose that large checksums for smaller keys, you should not choise 512bit rsa keys since they are insecure. >>> >>> If you stop using 512bit rsa keys, it should work just fine. >>> >> How and where should I specify these values? > > In the tool that created the privatekey/certificate, I assume that is your 'x509 certificate proxy' that you mentioned in the first mail. > > Love > -- Douglas E. Engert <[email protected]> Argonne National Laboratory 9700 South Cass Avenue Argonne, Illinois 60439 (630) 252-5444