What is the actual view about running CA with 4096 bit key


dear all,

i implement single tier ca environment. thinking ca key size: should maybe 4096 bit instead of 2048? nowadays, issued certificates 2048 bit long, better increase ca key size.

however, concerned, applications may break if using 4096 bit root ca key size. there known ms applications / servers / clients known break 4096 bit? example of this: exchange 2010, sharepoint, lync, wsus, scom, tmg 2010 etc.? not responsible 3rd parties, ms real-world exmaples ones highly welcome.

thanks

richard

i'm not sure official guidance can tell run of ms applications listed 4096-bit root ca key without problems.  typically compatibility issues seen @ boundaries 3rd party apps (ex: citrix netscaler supports 2048 max), , older clients.  but, since don't care 3rd party, if clients relatively modern don't think run problems applications have above.


Windows Server  >  Directory Services



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...