如何将Hashicorp Vault PKI的RSA证书最小密钥长度设为4096位?
Got it, let's break down exactly how to enforce a minimum 4096-bit RSA key length for your Vault PKI setup. There are two main scenarios to cover: updating an existing PKI role, and creating a new one. Plus, a quick note on updating the CA's own key if that's something you need.
Updating an Existing PKI Role
If you already have a role configured (let's say it's named app-server-role), you can update it to require 4096-bit keys with this command:
vault write pki/roles/app-server-role min_rsa_key_bits=4096
This setting tells Vault to reject any certificate signing request (CSR) that uses an RSA key shorter than 4096 bits. Clients will have to generate 4096-bit keys first before requesting a cert.
Creating a New PKI Role with 4096-bit Minimum
When setting up a new role, just include the min_rsa_key_bits parameter right from the start. Here's an example configuration for a role that allows subdomains of example.com:
vault write pki/roles/new-app-role \ allowed_domains="example.com" \ allow_subdomains=true \ max_ttl="720h" \ min_rsa_key_bits=4096
Verify the Setting Took Effect
To make sure your change stuck, read back the role's configuration:
vault read pki/roles/app-server-role
Look for the min_rsa_key_bits field in the output—it should show 4096.
Bonus: Updating the CA's Own Key to 4096 Bits
Important note: The above settings only affect the keys used by clients requesting certificates. If you want your PKI CA's own root/intermediate key to be 4096 bits, you'll need to regenerate the CA (this replaces the existing root cert, so plan carefully to avoid breaking trust across your systems):
vault write pki/root/generate/internal \ common_name="my-org-ca.example.com" \ key_type=rsa \ key_bits=4096 \ ttl="87600h"
Only do this if you're prepared to roll out the new root CA to all your trusted environments.
内容的提问来源于stack exchange,提问作者Yaakov Blank

