Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

6.1.5 Key Sizes - Subscriber #32

Closed
lachellel opened this issue Nov 23, 2016 · 4 comments
Closed

6.1.5 Key Sizes - Subscriber #32

lachellel opened this issue Nov 23, 2016 · 4 comments

Comments

@lachellel
Copy link
Contributor

Needs to be updated to align with NIST SP 800-131A and FIPS 186-4 AND larger key sizes and dates

Currently, Section 6.1.5 for subscriber certificates states:

(3) Subscriber Certificates

Validity period ending on or before 31 Dec 2013 Validity period ending after 31 Dec 2013
Digest algorithm SHA1*, SHA-256, SHA-384 or SHA-512 SHA-1*, SHA-256, SHA-384 or SHA-512
Minimum RSA modulus size (bits) 1024 2048
ECC curve NIST P-256, P-384, or P-521 NIST P-256, P-384, or P-521
Minimum DSA modulus and divisor size (bits) L= 2048, N= 224 or L= 2048, N= 256 L= 2048 N= 224 or L= 2048 N= 256
@lachellel lachellel modified the milestone: Section 2 and Section 6: First Draft Iteration Nov 25, 2016
@LarryFrank
Copy link

Can leave out the 2013 stuff. OBE. And maybe add the post 2030 requirements, as they will come into play soon - specifically for roots...

@lachellel
Copy link
Contributor Author

Remove all SHA-1
Minimum 2048
Allow ECC

@LarryFrank
Copy link

Remove all SHA-1
Minimum 2048
Allow ECC

Agree - but Roots (assuming 20 years) needs to be at least 3072 (maybe 4096...)

@lachellel
Copy link
Contributor Author

#28 for root

The option on the table is root is 4096

lachellel added a commit that referenced this issue Dec 15, 2016
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

No branches or pull requests

2 participants