Hi,

On 16/12/16 16:48, Sebastian Rubenstein wrote:
>
>> - a private key size of 4096 does not mean anything. What is more
>> important is that the CA certificate used to sign the client and server
>> certs is 4096 bits (or EC based) and that the remaining certs
>> (intermediate, server, client) are at least 2048 bit in strength;
>> Increasing the strenght beyond that is useless for now (RSA 2048 has not
>> been broken yet) and it will only slow things down.
>>
> There is no way for a customer like me to get hold of my VPN provider's 
> server and intermediate certificates to check if the cipher strength is at 
> least 2048 bits, correct?
>
>
the openvpn server actually sends this information to the client when it 
tries to connect, but it is quite hard to get at it. I don't have much 
time to investigate,but I'm curious what happens if the server has a 
2048bit certificate signed by a 1024bit CA - that should pop up 
somewhere in the logs, but I simply don't know when & where.

JJK


------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most 
engaging tech sites, SlashDot.org! http://sdm.link/slashdot
_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to