keygen.sh: why 3072-bit keys?

Wessel, Keith kwessel at illinois.edu
Wed May 31 11:01:29 EDT 2017


Hi, all,

One of our developers was looking at keygen.sh yesterday, reproducing its functionality elsewhere, and he noticed that it generates 3072-bit keys for the SP. I would have expected a 2048-bit key size. Obviously, the 3072-bit keys are that much more secure, but I'd think once you get past 2048 bits, it becomes somewhat academic.

Is there a reason that keygen.sh generates the larger keys? I'm wanting to know what advice I should give the developer who was asking. He's okay with 3072 bits but wondered why.

Thanks,
Keith



More information about the users mailing list