On 16/12/16 15:06, Dreetjeh D wrote:
Hi,
If i`m allowed again (:
>- a private key size of 4096 does not mean anything. What is more
>important is that the CA certificate used to sign the client and server
>certs is 4096 bits (or EC based) and that the remaining certs
>(intermediate, server, client) are at least 2048 bit in strength;
>Increasing the strenght beyond that is useless for now (RSA 2048 has not
>been broken yet) and*it will only slow things down*.
>JM2CW,
>JJK
>From client point of view, slowdown only when authenticating?
No slow down after that, except when rekeying occurs after set
time/byte interval (default 1 hr.)?
correct - the slowdown occurs whenever a (re)keying needs to be done:
when the connection starts and then every 1 hour (or XXX bytes,
depending on the config).
JJK
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, SlashDot.org! http://sdm.link/slashdot
_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users