Skip to Content.

cat-users - Re: [[cat-users]] EC radius certificate < 1024bits

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive


Re: [[cat-users]] EC radius certificate < 1024bits


Chronological Thread 
  • From: Stefan Winter <stefan.winter AT restena.lu>
  • To: Francesco Malvezzi <francesco.malvezzi AT unimore.it>, cat-users AT lists.geant.org
  • Subject: Re: [[cat-users]] EC radius certificate < 1024bits
  • Date: Thu, 1 Mar 2018 14:12:48 +0100
  • Openpgp: id=AD3091F3AB24E05F4F722C03C0DE6A358A39DC66; url=http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66

Hello,

> I have changed the radius certificate with a ECDH cert generated from
> OpenSSL (prime256v1).
>
> The sanity check CAT tool complains it is too short (< 1024 bits). May I
> ignore the warning?

The key length check was indeed written with the implicit assumption
that we're talking RSA keys.

For ECDH keys, you indeed ignore the warning, and I'll update the code
base to check for that.

It would be helpful to get a copy of your server cert as a test object.

However, out of curiosity: do you already use this in production? What
is the support landscape for EC certificates across typical client
devices? Do you see any incompatibilities?

Greetings,

Stefan Winter

--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette

Tel: +352 424409 1
Fax: +352 422473

PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me

http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66

Attachment: 0x8A39DC66.asc
Description: application/pgp-keys

Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.19.

Top of Page