Re: key length
Gert Doering <[email protected]>
| Newsgroups | gmane.network.openvpn.user |
|---|---|
| Message-ID | <[email protected]> |
Hi,
On Wed, Feb 21, 2024 at 02:39:04PM +0000, Hans via Openvpn-users wrote:
> Last week i got a reminder, that (at least in Germany by the BSI ) the minimum key-length has been changed to 3072 bits.
> And before someone is going to mention it: yes, I know that according to NIST, 2K keys could be used until 2030
>
> So, can Openvpn handle keys longer than 2K?
The actual asymmetric key handling (RSA certificates etc) is done by the
SSL library, there is no limitation imposed by OpenVPN. So 4k or even 8k
should be fine, it will just take much longer for the TLS negotiation, with
diminishing returns.
gert
--
"If was one thing all people took for granted, was conviction that if you
feed honest figures into a computer, honest figures come out. Never doubted
it myself till I met a computer with a sense of humor."
Robert A. Heinlein, The Moon is a Harsh Mistress
Gert Doering - Munich, Germany [email protected]
_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users
signature.asc
(application/pgp-signature, 630 B)
-----BEGIN PGP SIGNATURE----- iQGcBAEBAgAGBQJl1jHOAAoJEB2Cnv7KVigSawgL/1tbppGw1Mc2D5hnhuZj6XrG OioKjkhRHY4q10AWucKjRQkPRcj2Z21nxyrF6esI+zRMzEXy739tKcKlKiHsSyap Tboyyux4wzntkEFcAT9fy1kX2wLpj2x/Khahyb0KYwvigOGe+ta7P228HmK5xy1B qT+8JYmD+mWbBHNfU6I1ayy/LPmLyBOSMcKSBQlB+WnMFWHZgTx+oKpre366n5gm aq+96keWU/1SVQQU1M3fL7Pd4ZiaLvpR6YxILKksqU10Y5ZpV7eBm4Wbecjkf1+d 4oWjEd8kZrFXCmeTFcjA+hXf8AkUL1vOBXN7ZV3QyaivWC8o/X4sv7ycS9vwViPf ExkAMY0qnxrQ9L/XZAKbtm/iW2JWWPWX9zD51QpVZiNiawzRZOuVGtbyGo+HZaHP 04l5ljd8iP4EDTyvdOzkh/P3i/u8av9FNQL0aFKRxfUs15qfJYLHuQkaur9pwg3V wiGub2efYZXqjrXFADfUsZuH/nFJ5ZKI+3zg4rToKw== =al4w -----END PGP SIGNATURE-----