文章目录
- 参考
- 推荐限制
- RHEL相关配置
- man crypto-policies
- 包含的应用
- 使用方法是配置文件include
参考
https://csrc.nist.gov/pubs/sp/800/57/pt1/r2/final
https://www.linuxquestions.org/questions/linux-security-4/1024-bit-dsa-vs-2048-bit-rsa-4175439131/
https://csrc.nist.gov/CSRC/media/Projects/Key-Management/documents/transitions/Transitioning_CryptoAlgos_070209.pdf
https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-57p1r2007.pdf
推荐限制
If information is initially signed in 2009 and needs to remain secure for a maximum of ten years (i.e., from 2009 to 2019), a 1024 bit RSA key would not provide sufficient protection between 2011 and 2019 and, therefore, it is not recommended that 1024-bit RSA be used in this case. It is recommended that the algorithms and ke