#904686 ssl-cert: RSA keylength is getting a bit short

#904686#5
Date:
2018-07-26 16:13:28 UTC
From:
To:
The current default keylength for the snakeoil cert is 2048 bits. However,
these certs could now live for ten years (3650 days), which as I type
this could be upto 2028.

Various technical bodies are recently that for long-lived secrets,
a factoring modulus (i.e., RSA key size) of 3072 bits is recommended:

https://www.keylength.com/en/4/
https://www.keylength.com/en/compare/

2048b should be good until the year 2030, but we're approaching that now:

https://en.wikipedia.org/wiki/Key_size#Asymmetric_algorithm_key_lengths

While most commercial certificate authorities (CAs) give out 2048 bit
certficites, those are only valid for 1-2 years (90 days in the case
of Let's Encrypt), so the risk is much less in the short term.


Can "-newkey rsa:3072" be added to the ssl-cert script for better
future proofing?

#904686#12
Date:
2026-08-01 15:48:57 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
ssl-cert, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 904686@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Stefan Fritsch <sf@debian.org> (supplier of updated ssl-cert package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 01 Aug 2026 17:20:31 +0200
Source: ssl-cert
Architecture: source
Version: 1.2.0
Distribution: unstable
Urgency: medium
Maintainer: Debian Apache Maintainers <debian-apache@lists.debian.org>
Changed-By: Stefan Fritsch <sf@debian.org>
Closes: 904686 929121
Changes:
 ssl-cert (1.2.0) unstable; urgency=medium
 .
   [ Stefan Fritsch ]
   * Bump standards-version and remove Priority from control file
   * Increase default key length to 3072, but don't replace existing
     2048 bit keys. Closes: #904686
   * Enable Salsa-CI
   * Allow separate key/cert files for the non generate-default-snakeoil
     case, too. Closes: #929121
   * Allow to override CN and SubjectAltName from command line.
 .
   [ Luca Boccassi ]
   * Install and use sysusers.d config file instead of adduser for the
     ssl-cert group.
Checksums-Sha1:
 ebfc48d574453dd32e6cf5e6ee6bbbba697eaff7 1645 ssl-cert_1.2.0.dsc
 6d07dd27dd09dcacd60d4353616b532364f558a4 33344 ssl-cert_1.2.0.tar.xz
 d8051d4532fdc130e06840d9c2340ec83ab91b1f 7085 ssl-cert_1.2.0_source.buildinfo
Checksums-Sha256:
 bdb935dd6cb613ac55e0d637738c286e226d76df21f28c48cb9b534582cf4961 1645 ssl-cert_1.2.0.dsc
 2615b043c1d692f8ce64e72e3e9acf6c0fff92cfb899e53e98226ef4031f150a 33344 ssl-cert_1.2.0.tar.xz
 33cb20fc58feb9f8be31efe73f1c307269293aacdad20f473c4a1f55e3ce8738 7085 ssl-cert_1.2.0_source.buildinfo
Files:
 473cede5d7fad1259844c02a0c711719 1645 utils optional ssl-cert_1.2.0.dsc
 d3397258772729e57dc86feb18793085 33344 utils optional ssl-cert_1.2.0.tar.xz
 c3373a38f78801a184ec071d1fb6e304 7085 utils optional ssl-cert_1.2.0_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEOpiNza8JqByyYYsxxodfNUHO/eAFAmpuD3YACgkQxodfNUHO
/eAwRBAAhqUzmIF6ywQyuDS+lWkL97U//wqBK9Fo34uvaqsCPOD9W2B9YHq7UYbh
T6QCaEa9R+ny1xlR0sYw7KQJdE4rhV3abv1avn30YgoQQk+fcsyWuR6Qb90tJd0W
Ha55JspwkhV4IEzmX9VZk9vYvXAhNnBuv+RgVQRSjzajvTOCXMfDGQEMXveU8wbA
0hoH49MoMYc1eYHuD8fw7LHIGwRoE4BSS7hz7aGKLRImnbgZRSDUdlxAZLRaPicY
2TosAYn9euj7uvfifq934bPyvShQEjVmUjzReLWTdl/M5nyFdmOvkWf8JtqWopoY
0UzbF8TJNBMBXfekUsQXwQn/czjDjXiwHDTTB/5fMiTjPGaQA8wS29p3DFvR2m1d
kwn03zHpH8mR+UDJnIlAsXAP/cUHtwR9tQXNixUdeYN6IYL5BaHekGa994WkxVn6
uL7fe6UsrVNV2DdH3SN7XjM0/oppr60ziuLkbq4wU6RA2CuAkqcclkmySIFWs6Lu
fjcn3YNaBTmru/HxSaP/OLwE5j33S74JktgtEsWEGGhzUdw3dzMJvPawTKZ7V+Qe
H4hgm6vMA7b1TllL3cgqoGxa32dNOKQ17dM0SUXwdizyWDD+PPZ92XbK+ISJcPmd
7IY4hbJccHilF27OesuYGeK+30MqJuNlDvhEF5QtAoxQj8qelKs=
=K2RS
-----END PGP SIGNATURE-----