Project

General

Profile

Actions

User story #6253

closed

User story #6363: Secure agent/server communication

Generate 4k rsa keys for agents

Added by Florian Heigl about 9 years ago. Updated about 6 years ago.

Status:
Released
Priority:
3
Category:
System integration
Target version:
UX impact:
Suggestion strength:
User visibility:
Effort required:
Name check:
Fix check:
Regression:

Description

Hi,

CFEngine by default uses a 2Kbit RSA key.
There is no way in cf-key to change the value as of now.

On the other hand it is just a key, so it would be possible to create a far safer 4k one.
it would be viable to pre-seed that key, even for all hosts since rudder already has it's own CFEngine package.

I think on the root server / relay servers it is even more important, so at worst it could just be put in docs & manually done when setting up the root / relays.


Subtasks 1 (0 open1 closed)

User story #12095: Generate 4k rsa keys for agents during factory resetReleasedBenoît PECCATTEActions

Related issues 2 (0 open2 closed)

Related to Rudder - User story #8552: Add a command to show agent auth infoReleasedBenoît PECCATTEActions
Related to Rudder - User story #12241: Backport key size option for cf-keyReleasedBenoît PECCATTEActions
Actions

Also available in: Atom PDF