HPE OneView
cancel
Showing results for 
Search instead for 
Did you mean: 

Increase Public Key size to RSA4096 in certificate signing request

 
Lenny_Juarbe
Occasional Contributor

Increase Public Key size to RSA4096 in certificate signing request

Hello, 

I am trying to import CA signed certs for my OneView 4.00.9 appliances.  My CA admin was able to add the correct template with the following:

X509v3 Key Usage:

Digital Signature, NonRepudiation, Key Encipherment

X509v3 Extended Key Usage:

TLS Web ServerAuthentication, TLS Web Client Authentication

However, when submitting the request it complained about the Public Key size.  Apparently our policy is to use RSA 4096 bits. 

Question is how do you increase the Public Key size in the request to 4096?  

Any help is greatly appreciated.

3 REPLIES 3
ChrisLynchHPE
Neighborhood Moderator

Re: Increase Public Key size to RSA4096 in certificate signing request

Unfortunately, it is not possible to create a CSR with 4096 key length today.  With HPE OneView 4.10 and the appliance put into CNSA Mode (which can break communication with legacy and older systems that cannot support the stronger encryption and cyphers), the CSR would generate a 3072 bit length key.


Accept or Kudo

Lenny_Juarbe
Occasional Contributor

Re: Increase Public Key size to RSA4096 in certificate signing request

Thank you Chris for the reply.  

Just so I understand you correctly, with CNSA Mode the strongest encryption the appliance will generate is 3072 bits.  Is it then possible to generate a csr using openssl with the key size set to 4096 and import the cert?  In other words, does OneView accept/support certs with a 4096 bit Public key size generated by a csr outside of the appliance's own mechanism?

ChrisLynchHPE
Neighborhood Moderator

Re: Increase Public Key size to RSA4096 in certificate signing request

Unfortunately no.  HPE OneView must generate the CSR today.  We do not have a method to import both the private and publicly signed key to the appliance.


Accept or Kudo