Weak Crypto Key Length¶
What does this mean ?¶
A cryptographic key is too short when its effective strength falls below the security requirements of the algorithm and protocol. Raw bit lengths are not comparable across RSA, elliptic curves and symmetric encryption. A long string is also not necessarily a high-entropy key.
What can happen ?¶
A weak key may allow an attacker to forge signatures or recover protected data more cheaply than expected. Correct key length does not compensate for a broken mode, reused nonce, leaked private key or incorrect verification. Protection requirements depend on the lifetime and sensitivity of the data.
Recommendation¶
Use the algorithm and size required by the reviewed protocol and organizational policy. For a new integration that specifically requires RSA and supports it, 3072-bit RSA is a common choice targeting roughly 128-bit classical strength. Do not replace an existing protocol's algorithm or key type without checking compatibility. Modern approved elliptic-curve protocols have different parameter choices; avoid selecting obscure curves merely because a library exposes them.
Generate keys with the platform's cryptographic generator or a managed key service. Keep private material in a protected keystore, hardware-backed service or appropriately restricted secret store, with rotation and recovery procedures. Never print private keys to logs. For AES, use a randomly generated key of a supported size and an authenticated mode; do not treat an ordinary password as an AES key.
Algorithm transitions, including post-quantum requirements, need a separate protocol and migration review. Increasing RSA key size alone is not a post-quantum strategy.
Sample Code¶
These examples generate an RSA3072 key for a protocol that requires RSA. They do not export, print or persist the private key. Secure storage and algorithm-specific signing/encryption padding remain part of the implementation. Do not generate a fresh signing key per request when other systems rely on a stable public key.
cryptography dependency:
from cryptography.hazmat.primitives.asymmetric import rsa
private_key = rsa.generate_private_key(public_exponent=65537, key_size=3072)
public_key = private_key.public_key()
import { generateKeyPairSync } from 'node:crypto';
const { privateKey, publicKey } = generateKeyPairSync('rsa', { modulusLength: 3072 });
Without encoding options, Node returns key objects rather than a string suitable for accidental logging. Key objects still need careful handling and must not be logged.
Modern .NET:
using var rsa = System.Security.Cryptography.RSA.Create(3072);
// Use a reviewed signing/encryption API and protect any exported private material.
var generator = java.security.KeyPairGenerator.getInstance("RSA");
generator.initialize(3072, new java.security.SecureRandom());
var keyPair = generator.generateKeyPair();
A protocol selecting EC should name an appropriate supported curve instead; RSA length values cannot be copied into an EC configuration.
$key = openssl_pkey_new([
'private_key_type' => OPENSSL_KEYTYPE_RSA,
'private_key_bits' => 3072,
]);
if ($key === false) throw new RuntimeException('Key generation failed');
Do not send private key details to an HTTP response or error log.
privateKey, err := rsa.GenerateKey(rand.Reader, 3072)
if err != nil {
return err
}
if err := privateKey.Validate(); err != nil {
return err
}
// Use the key through a reviewed protocol. Never fmt.Println(privateKey).
Imports: crypto/rand and crypto/rsa. This fragment belongs to a function returning an error.
Regression checks¶
Inspect public key metadata to verify algorithm and size without recording the private key. Exercise a sign/verify or encrypt/decrypt fixture using the exact protocol settings, and reject an incompatible or undersized imported key. Confirm failed generation stops initialization. Search test output, logs and crash reporting for accidental private-key export; use ephemeral test keys only.