]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
get_algorithms.py: use FIPS compatible bit size
authorMark Andrews <marka@isc.org>
Thu, 12 Jan 2023 22:48:53 +0000 (09:48 +1100)
committerMark Andrews <marka@isc.org>
Mon, 3 Apr 2023 02:44:27 +0000 (12:44 +1000)
The minimum RSA key size that can be used in FIPS mode is 2048 bits.

bin/tests/system/get_algorithms.py

index e21e208ce9299b06368ed0e0adc0a65fd18996db..ca4b68c2d120143bc3e383593db5e66b72acdcfd 100755 (executable)
@@ -53,9 +53,9 @@ class AlgorithmSet(NamedTuple):
     "disable-algorithms" configuration option."""
 
 
-RSASHA1 = Algorithm("RSASHA1", 5, 1280)
-RSASHA256 = Algorithm("RSASHA256", 8, 1280)
-RSASHA512 = Algorithm("RSASHA512", 10, 1280)
+RSASHA1 = Algorithm("RSASHA1", 5, 2048)
+RSASHA256 = Algorithm("RSASHA256", 8, 2048)
+RSASHA512 = Algorithm("RSASHA512", 10, 2048)
 ECDSAP256SHA256 = Algorithm("ECDSAP256SHA256", 13, 256)
 ECDSAP384SHA384 = Algorithm("ECDSAP384SHA384", 14, 384)
 ED25519 = Algorithm("ED25519", 15, 256)