6.0.0-beta1
▾
Tasks
New Task
Search
Photos
Wiki
▾
Tickets
New Ticket
Search
dev.horde.org
Toggle Alerts Log
Help
11/6/25
H
istory
A
ttachments
C
omment
W
atch
Download
Comment on [#12099] create gpg keys for the 21th century
*
Your Email Address
*
Spam protection
Enter the letters below:
.__ ._.. . ..__ [__) | \ / || \ | _|_ \/ \__||__/
Comment
>> make default pgp keylength 2048 >> The issue is not security but performance -- generating sufficient >> random bits via a web request can take ages (minutes) on certain >> systems. These kind of requests can block PHP and cause DoS problems >> if a user keeps reloading the page because the request is taking too >> long. > > I partly agree but i guess you could dos just as well using 1024 bit keys.... > > but indeed i first tried to make it configurable in this patch: > https://github.com/immrr/horde/commit/63315234f112e138e48b36b06e5e30c59bb7a7c8 > > but i reverted this patch, since it was suggested that 2048 could be > set as hardcoded default and the patch wrongly put the option in > prefs.php. > > i can try to implement the feature again via conf.php, would you > consider to merge this? because e.g. in our setup we could easily > enable longer keys, since we have an entropy key.
Attachment
Watch this ticket
N
ew Ticket
M
y Tickets
S
earch
Q
uery Builder
R
eports
Saved Queries
Open Bugs
Bugs waiting for Feedback
Open Bugs in Releases
Open Enhancements
Enhancements waiting for Feedback
Bugs with Patches
Enhancements with Patches
Release Showstoppers
Stalled Tickets
New Tickets
Horde 5 Showstoppers