Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 715470 - net-misc/sendmail: Possibly inadequate key sizes for RSA
Summary: net-misc/sendmail: Possibly inadequate key sizes for RSA
Status: UNCONFIRMED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Auditing (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-03-30 15:17 UTC by Sam James
Modified: 2022-03-27 00:15 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-03-30 15:17:18 UTC
This needs investigation, but I'm splitting it out from another bug.

From Seth Robertson here: https://bugs.gentoo.org/699414#c0
> I also am *extremely* dubious about the default of 512 bits of RSA key being
> used by sendmail for this key generation.  The "enhanced" default of 1024
> bits for FIPS is pretty dubious as well (though possibly required).  I'm not
> sure what this RSA key is being used for, but 512 bits could be broken for
> $75 in 2015
> https://arstechnica.com/information-technology/2015/10/breaking-512-bit-rsa-
> with-amazon-ec2-is-a-cinch-so-why-all-the-weak-keys/ so I cannot imagine it
> is a good default.  However, technically this is a different matter that the
> primary bug and nothing to do with gentoo patches being broken.  See
> RSA_KEYLENGTH in sendmail.h if you want to fix it as an extremely good idea.

I have filed this as bug . Note that net-mail/sendmail is maintainer-needed,
so a patch would be appreciated.
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-03-30 15:17:50 UTC
(In reply to Sam James (sam_c) (security padawan) from comment #0)
> This needs investigation, but I'm splitting it out from another bug.
> 
> From Seth Robertson here: https://bugs.gentoo.org/699414#c0
> > I also am *extremely* dubious about the default of 512 bits of RSA key being
> > used by sendmail for this key generation.  The "enhanced" default of 1024
> > bits for FIPS is pretty dubious as well (though possibly required).  I'm not
> > sure what this RSA key is being used for, but 512 bits could be broken for
> > $75 in 2015
> > https://arstechnica.com/information-technology/2015/10/breaking-512-bit-rsa-
> > with-amazon-ec2-is-a-cinch-so-why-all-the-weak-keys/ so I cannot imagine it
> > is a good default.  However, technically this is a different matter that the
> > primary bug and nothing to do with gentoo patches being broken.  See
> > RSA_KEYLENGTH in sendmail.h if you want to fix it as an extremely good idea.
> 
> I have filed this as bug . Note that net-mail/sendmail is maintainer-needed,
> so a patch would be appreciated.

Ignore the last few lines.. :)