Security/Guidelines/Key Management: Difference between revisions

Jump to navigation Jump to search
Line 90: Line 90:


=== Protection of user keys ===
=== Protection of user keys ===
As SSH keys are rarely renewed the minimum recommended settings are higher than other keys. If you follow a strict key renewal period of '''less than 2 years''', it is reasonable to use RSA 2048 bits or ECDSA 224 bits keys.
* Protected by strong passphrase.
* Protected by strong passphrase.
* Never copied to another system than your own workstation/personal physical disks/tokens.
* Never copied to another system than your own workstation/personal physical disks/tokens.
Confirmed users
529

edits

Navigation menu