DSA 2048 bit keys?

Iain Morgan imorgan at nas.nasa.gov
Sat Sep 27 08:00:08 EST 2014


On Fri, Sep 26, 2014 at 21:12:54 +0000, Scott Neugroschl wrote:
> Is there a reason ssh-keygen restricts DSA keys to exactly 1024 bits, given that NIST is recommending a minimum of 2048?
> 
> http://csrc.nist.gov/publications/nistpubs/800-131A/sp800-131A.pdf
> 

Yes, a conflict between the RFC and NIST. Use ecdsa instead.

-- 
Iain Morgan


More information about the openssh-unix-dev mailing list