[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]



About Lenny and Squeeze: DSA
Application: ssh (openssh-server)

in general a RSA and DSA keypair are being used for ssh,
now regarding RSA one can freely choose the length of the key,
but for DSA this is fixed to 1024 bits,
this is on the lower part of the recommendations of FIPS 186-3,
which specifies (1024,160), (2048,224), (2048,256), and (3072,256).

So why isn't it possible to choose one the longer keylengths for DSA?

Or, (i'm not expert), but it seems logical not to use the DSA keypairs
(just deleting them), and only use the RSA keypairs (or am i missing


Reply to: