RE: PKINIT for gsissh

Ali Gholami <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Message-ID <[email protected]>
Hi Douglas,

I just got some feedback that Globus community is also intersted to use larger defaul RSA keys and I submited as a bug to be fixed in the new releases. The most obvious reason for using small keys was the overhead with the larger keys.

Best
Ali 





________________________________________
From: Douglas E. Engert [[email protected]]
Sent: Tuesday, October 04, 2011 5:43 PM
To: [email protected]
Subject: Re: PKINIT for gsissh

Ali,
You may want to post a question about why are 512 bit RSA keys
in proxy certificates still being used, and how to use larger
keys to: [email protected]

On 10/4/2011 10:26 AM, Love Hörnquist Åstrand wrote:
>
> 4 okt 2011 kl. 15:41 skrev Ali Gholami:
>
>>> Hi Love,
>>>
>>>> Well, when I debug it, I see "indata.length = 83" and "sig->data" which I think is the "rsa" size equal to 64.  My question was the purpose of this if clause: "if (indata.data != data->data)".
>>>
>>> you have 512byte rsa keys, todays larger digests (sha512) doesn't fit inside the rsa encryption.
>>>
>>> While the code should not choose that large checksums for smaller keys, you should not choise 512bit rsa keys since they are insecure.
>>>
>>> If you stop using 512bit rsa keys, it should work just fine.
>>>
>> How and where should I specify these values?
>
> In the tool that created the privatekey/certificate, I assume that is your 'x509 certificate proxy' that you mentioned in the first mail.
>
> Love
>

--

  Douglas E. Engert  <[email protected]>
  Argonne National Laboratory
  9700 South Cass Avenue
  Argonne, Illinois  60439
  (630) 252-5444
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.