4 ms·
DSA - maybe. RSA - what's wrong with that one given you have a 4096 bit key?
by nobodyshere 7y ago
DSA - maybe. RSA - what's wrong with that one given you have a 4096 bit key?
- jjjbokma 7y agoThe article uses RSA 2048 :-(. See https://blog.g3rt.nl/upgrade-your-ssh-keys.html https://blog.g3rt.nl/upgrade-your-ssh-keys.html for why Ed25519 should be preferred, even over RSA 4096 (assuming it's supported, of course).
- nobodyshere 7y agoWhen it comes to 4096 the only viable benefit seems to be the key size and performance. While I certainly agree with that and I wish I could use ed25519, I can't use it with my security keys. Yubikey currently supports 4096 bit RSA keys as a part of GPG applet. There's a PIV module, however in terms of elliptic curves it only has ec256 and ec384 and I still can't get ssh and pkcs11 to pick up anything other than built-in 2048 RSA keys.