Originally created by @venigo on GitHub (Sep 15, 2016).
Howto set all certs on 4096 to get a better score?
I run the script like ./letsencrypt.sh -c
The output:
1 Sent by server
Fingerprint SHA1: 1bc48b413fb0fd446161f284050ee7d955a2c13d
Pin SHA256: 8d4OB2KT3OBcUvgs8BiZrqjPhNyozJNNBBexbQ0Q9MA=
RSA 4096 bits (e 65537) / SHA256withRSA
2 Sent by server Let's Encrypt Authority X3
Fingerprint SHA1: e6a3b45b062d509b3382282d196efe97d5956ccb
Pin SHA256: YLh1dUR9y6Kja30RrAn7JKnbQG/uEtLMkBgFF2Fuihg=
RSA 2048 bits (e 65537) / SHA256withRSA
3 In trust store DST Root CA X3 Self-signed
Fingerprint SHA1: dac9024f54d8f6df94935fb1732638ca6ad77c13
Pin SHA256: Vjs8r4z+80wjNcr1YKepWQboSIRi63WsWXhIMN+eWys=
RSA 2048 bits (e 65537) / SHA1withRSA
Weak or insecure signature, but no impact on root certificate
Originally created by @venigo on GitHub (Sep 15, 2016).
Howto set all certs on 4096 to get a better score?
I run the script like ./letsencrypt.sh -c
The output:
> 1 Sent by server
> Fingerprint SHA1: 1bc48b413fb0fd446161f284050ee7d955a2c13d
> Pin SHA256: 8d4OB2KT3OBcUvgs8BiZrqjPhNyozJNNBBexbQ0Q9MA=
> RSA 4096 bits (e 65537) / SHA256withRSA
> 2 Sent by server Let's Encrypt Authority X3
> Fingerprint SHA1: e6a3b45b062d509b3382282d196efe97d5956ccb
> Pin SHA256: YLh1dUR9y6Kja30RrAn7JKnbQG/uEtLMkBgFF2Fuihg=
> RSA 2048 bits (e 65537) / SHA256withRSA
> 3 In trust store DST Root CA X3 Self-signed
> Fingerprint SHA1: dac9024f54d8f6df94935fb1732638ca6ad77c13
> Pin SHA256: Vjs8r4z+80wjNcr1YKepWQboSIRi63WsWXhIMN+eWys=
> RSA 2048 bits (e 65537) / SHA1withRSA
> Weak or insecure signature, but no impact on root certificate
The certificates generated by this script are using 4096 bit RSA keys by default, the 2048 bit key ist the root CA key which was generated by Let's Encrypt.
@lukas2511 commented on GitHub (Sep 15, 2016):
The certificates generated by this script are using 4096 bit RSA keys by default, the 2048 bit key ist the root CA key which was generated by Let's Encrypt.
The certificates generated by this script are using 4096 bit RSA keys by
default, the 2048 bit key ist the root CA key which was generated by Let's
Encrypt.
@venigo commented on GitHub (Sep 15, 2016):
Thank you for the reply,
So how can I fix this (not an expert user).
Remove the 2 2048 bit ca keys? How?
2016-09-15 10:43 GMT+02:00 Lukas Schauer notifications@github.com:
> The certificates generated by this script are using 4096 bit RSA keys by
> default, the 2048 bit key ist the root CA key which was generated by Let's
> Encrypt.
>
> —
> You are receiving this because you authored the thread.
> Reply to this email directly, view it on GitHub
> https://github.com/lukas2511/dehydrated/issues/276#issuecomment-247271052,
> or mute the thread
> https://github.com/notifications/unsubscribe-auth/AMDb4UlUb55yVylR5u46zA2tWc5hGFRHks5qqQU-gaJpZM4J9lsz
> .
@venigo , there is no further action required from your side or this repository owner, everything is working as it should and as you expect.
You can not change anything related to the intermediate cert or ca cert.
Google is your friend to get more knowledge on digital certs.
@minagerges commented on GitHub (Sep 15, 2016):
@venigo , there is no further action required from your side or this repository owner, everything is working as it should and as you expect.
You can not change anything related to the intermediate cert or ca cert.
Google is your friend to get more knowledge on digital certs.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @venigo on GitHub (Sep 15, 2016).
Howto set all certs on 4096 to get a better score?
I run the script like ./letsencrypt.sh -c
The output:
@lukas2511 commented on GitHub (Sep 15, 2016):
The certificates generated by this script are using 4096 bit RSA keys by default, the 2048 bit key ist the root CA key which was generated by Let's Encrypt.
@venigo commented on GitHub (Sep 15, 2016):
Thank you for the reply,
So how can I fix this (not an expert user).
Remove the 2 2048 bit ca keys? How?
2016-09-15 10:43 GMT+02:00 Lukas Schauer notifications@github.com:
@venigo commented on GitHub (Sep 15, 2016):
Is it in the sh script..
Is it possible to add --rsa-key-size 4096?
@minagerges commented on GitHub (Sep 15, 2016):
@venigo , there is no further action required from your side or this repository owner, everything is working as it should and as you expect.
You can not change anything related to the intermediate cert or ca cert.
Google is your friend to get more knowledge on digital certs.