Bug#751556: opendkim: Set default MinimumKeyBits to 2048

2014-11-29 Thread Kurt Roeckx
On Fri, Nov 28, 2014 at 05:01:56PM -0500, Scott Kitterman wrote: > I did investigate this and there is a valid reason for this. There are DNS > service providers that limit TXT records to a single 255 character string > (even though DNS has no such limit). 2048 bit key records won't fit. I cou

Bug#751556: opendkim: Set default MinimumKeyBits to 2048

2014-11-28 Thread Scott Kitterman
I did investigate this and there is a valid reason for this. There are DNS service providers that limit TXT records to a single 255 character string (even though DNS has no such limit). 2048 bit key records won't fit. DKIM is designed to give some minimal level of assurance the message hasn't

Bug#751556: opendkim: Set default MinimumKeyBits to 2048

2014-06-14 Thread Kurt Roeckx
Package: opendkim Version: 2.9.2-1 Severity: important Hi, It seems that the default MinimumKeyBits is still set to 1024. Please change that to 2048. All certificates for server authentication (what DKIM does) with RSA keys smaller than 2048 should either have expired before 2014 or should have