Hi, On 16/12/16 16:48, Sebastian Rubenstein wrote: > >> - a private key size of 4096 does not mean anything. What is more >> important is that the CA certificate used to sign the client and server >> certs is 4096 bits (or EC based) and that the remaining certs >> (intermediate, server, client) are at least 2048 bit in strength; >> Increasing the strenght beyond that is useless for now (RSA 2048 has not >> been broken yet) and it will only slow things down. >> > There is no way for a customer like me to get hold of my VPN provider's > server and intermediate certificates to check if the cipher strength is at > least 2048 bits, correct? > > the openvpn server actually sends this information to the client when it tries to connect, but it is quite hard to get at it. I don't have much time to investigate,but I'm curious what happens if the server has a 2048bit certificate signed by a 1024bit CA - that should pop up somewhere in the logs, but I simply don't know when & where.
JJK ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, SlashDot.org! http://sdm.link/slashdot _______________________________________________ Openvpn-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/openvpn-users
