Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Require RSA keys of minimum 2048 bits #661

Merged
merged 1 commit into from
Dec 28, 2024

Conversation

anakinj
Copy link
Member

@anakinj anakinj commented Dec 28, 2024

Description

The JWA spec states for the RS and PS algos: "A key of size 2048 bits or larger MUST be used with these algorithms"

https://datatracker.ietf.org/doc/html/rfc7518#section-3.3
https://datatracker.ietf.org/doc/html/rfc7518#section-3.5

Fixes #635

Checklist

Before the PR can be merged be sure the following are checked:

  • There are tests for the fix or feature added/changed
  • A description of the changes and a reference to the PR has been added to CHANGELOG.md. More details in the CONTRIBUTING.md

@anakinj anakinj merged commit c073c98 into jwt:main Dec 28, 2024
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

encode() raises an RSA lib error when using a small RSA PSS key
1 participant