diff options
author | Daniel Kahn Gillmor <[email protected]> | 2017-09-07 22:39:37 +0000 |
---|---|---|
committer | Andre Heinecke <[email protected]> | 2019-02-28 10:00:31 +0000 |
commit | 121286d9d1506dbaad9ba33bae2e459814fe5849 (patch) | |
tree | c02632295e6acfd09468d9868773deab993ef8f3 /sm/certreqgen-ui.c | |
parent | conf: New option --show-socket. (diff) | |
download | gnupg-121286d9d1506dbaad9ba33bae2e459814fe5849.tar.gz gnupg-121286d9d1506dbaad9ba33bae2e459814fe5849.zip |
gpgsm: default to 3072-bit keys.
* doc/gpgsm.texi, doc/howto-create-a-server-cert.texi: : update
default to 3072 bits.
* sm/certreqgen-ui.c (gpgsm_gencertreq_tty): update default to
3072 bits.
* sm/certreqgen.c (proc_parameters): update default to 3072 bits.
* sm/gpgsm.c (main): print correct default_pubkey_algo.
--
3072-bit RSA is widely considered to be 128-bit-equivalent security.
This is a sensible default in 2017.
Signed-off-by: Daniel Kahn Gillmor <[email protected]>
Gbp-Pq: Topic update-defaults
Gbp-Pq: Name 0014-gpgsm-default-to-3072-bit-keys.patch
(cherry picked from commit 7955262151a5c755814dd23414e6804f79125355)
Diffstat (limited to 'sm/certreqgen-ui.c')
-rw-r--r-- | sm/certreqgen-ui.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/sm/certreqgen-ui.c b/sm/certreqgen-ui.c index b131d7db5..bbc74a566 100644 --- a/sm/certreqgen-ui.c +++ b/sm/certreqgen-ui.c @@ -138,7 +138,7 @@ gpgsm_gencertreq_tty (ctrl_t ctrl, estream_t output_stream) unsigned int nbits; int minbits = 1024; int maxbits = 4096; - int defbits = 2048; + int defbits = 3072; const char *keyusage; char *subject_name; membuf_t mb_email, mb_dns, mb_uri, mb_result; |