Subject: Re: 1024 bit key considered insecure (sshd)
To: Karsten W. Rohrbach <karsten@rohrbach.de>
From: Martin Husemann <martin@duskware.de>
List: tech-security
Date: 08/29/2002 10:45:29
On Thu, Aug 29, 2002 at 09:12:32AM +0200, Karsten W. Rohrbach wrote:
> increasing the server's key width imposes a higher processing cost for
> the initial handshake. efficiency of the cipher used for transit
> encryption is not directly affected.

You are aware that the current default key length already causes ~ 60s initial
handshake on hardware still in production use? (The Sparc Station 2 used as
a NAT gateway at work, for example.)

So bumping up the default is no good idea. More prominently pointing the user
at the switch may be.

Martin