Skip to content

Conversation

grooverdan
Copy link

512 bits in a test case seems a little outdated.

2432 is from the default in gnutls certtool

@exarkun
Copy link
Member

exarkun commented Aug 10, 2014

Thanks for your interest in pyOpenSSL.

These certificates are generated for the test suite's use only. They're not used by any production pyOpenSSL code. There's no reason to make them as large as the current security recommendations might suggest. Instead, there's a reason to make them as small as possible - because generating them takes time and uses up system entropy.

This suggests that 512 bits is still a suitable value to use here.

@exarkun exarkun closed this Aug 10, 2014
@grooverdan grooverdan deleted the test_real_cert_sizes branch August 11, 2014 01:52
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Aug 24, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants