Hi everybody,

I am a bit out of the loop as far as cryptography algorithms and recommended key sizes are concerned. I have been using the same ssh and gpg keys for a long time.

However, I need to generate a few new keys (both ssh and gpg) that should meet high security standards (private use, but paranoid) and was wondering what options are the most common and recommended ones you are using today?

Thanks a lot to everybody in advance!

    • username@lemm.eeOP
      link
      fedilink
      arrow-up
      6
      ·
      4 days ago

      Thanks! Cool video, I like her style. (Will look into the specifics of ed25519 out of interest when I have time… So, most probably not and I’ll just use it ;-D)

      • mlaga97@lemmy.mlaga97.space
        link
        fedilink
        arrow-up
        4
        arrow-down
        1
        ·
        3 days ago

        RSA4096 has a bit of an edge over ed25519 both in effective key size as well as support by things like YubiKeys and other HSMs that is beneficial for GPG but not really helpful for SSH.

  • mlaga97@lemmy.mlaga97.space
    link
    fedilink
    arrow-up
    2
    ·
    3 days ago

    SSH generally best to use ed25519, for GPG RSA4096 is better supported by HSMs and slightly more secure for longer-lived keys like root keys.

  • tla@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    3 days ago

    Others have provided the answer but if you want to explore system wide crypto policies check out update-crypto-policies

  • JubilantJaguar@lemmy.world
    link
    fedilink
    arrow-up
    1
    arrow-down
    4
    ·
    3 days ago

    The correct answer to this question should be ''Whatever is the current default".

    If we have to ask and answer such questions as this (I’m unconvinced), then something is really wrong.