If you want to check how many bits your key is, use
ssh-keygen -l -f ~/.ssh/your_key.pub
(It wasn't mine, while it is an older key, mine is larger than 768 thankfully)
Edit: look at timdorr's example for a better visual.
If you want to check how many bits your key is, use
ssh-keygen -l -f ~/.ssh/your_key.pub
(It wasn't mine, while it is an older key, mine is larger than 768 thankfully)
Edit: look at timdorr's example for a better visual.
ssh-keygen -l -f ~/.ssh/id_rsa.pub
You'll get an output like so: ⚡~ $ ssh-keygen -l -f ~/.ssh/id_rsa.pub
2048 f6:2d:94:54:c0:96:18:64:24:fb:c2:ad:ed:6a:1d:68 timdorr@Pixelicious.local (RSA) 4096 63:f2:23:00:c9:0d:07:3b:6d:ad:4d:a9:98:32:f5:25 ***@*** (RSA)
Am I good?is this something we should be upgrading (like to 4096) in the near future?
- 180x per doubling bit size would be - 512 doubled twice, would mean 3 days * 180 * 180 = 97,200 days
I think you're safe.
First, 2048 bits is not 512 bits doubled twice, but rather doubled 1536 times (512 doubled twice would be 514). If this were a symmetric cipher, you could stop here and conclude that a 2048 bit key was 2^1536 times stronger than a 512 bit key.
However, RSA has diminishing returns on security as you increase the key length. The strength is determined by the complexity of the GNFS, the fastest known way of breaking RSA[1]. That tells us that breaking 256-bit RSA takes ~2^46 operations, 512-bit RSA takes ~2^63, 2048-bit RSA takes ~2^116, and 4096-bit RSA takes ~2^156. 2^116 is a lot of operations - they say the amount of energy required to break that would be nearly enough to boil all the water on earth.
[1] http://crypto.stackexchange.com/questions/8687/security-stre...
Not wanting to be alarmist, but what you're saying is that someone breaking my ssh key (which is 2048 bits) is the end of the world...
As with RSA, this command generates a public and private key file. Put the public key in the authorized_keys file on the server side.
You'll need OpenSSH 6.4 on both the server and the client side. If you have an older version, I would not recommend upgrading outside of your operating system's normal upgrade channel because then you'll be responsible for security updates. Instead I would wait until your operating system has it.
$ ssh-keygen -t ed25519
As usual, on the server, you do something like $ cat generated-key.pub >> ~you/.ssh/authorized_keys
EDIT: sibling post was quicker off the bat. Oh well, that'll teach me to not refresh a tab :p for file in $(ls ~/.ssh/*.pub); do ssh-keygen -lf $file; done find ~/.ssh -name '*.pub' | xargs ssh-keygen -lf
Here's a simple bash function to check all your GitHub keys: function check_github_keys {
username=$1
i=0
curl -sw "\n" "https://github.com/${username}.keys" | while IFS="\n" read -r line ; do
tmp=`mktemp -t githubkey`;
echo "$line" > $tmp
res=$(ssh-keygen -lf $tmp)
rm $tmp
((i=i+1))
echo "${username}.keys:${i} ${res/ $tmp/}"
done
}
Invoke as: check_github_keys <username>
I'm sure there's a better way to write that one though!find ~/.ssh -name '*.pub' -print0 | xargs -0 ssh-keygen -lf
ssh-add -l
to list all your registered keys.