Hi everybody,

I am a bit out of the loop as far as cryptography algorithms and recommended key sizes are concerned. I have been using the same ssh and gpg keys for a long time.

However, I need to generate a few new keys (both ssh and gpg) that should meet high security standards (private use, but paranoid) and was wondering what options are the most common and recommended ones you are using today?

Thanks a lot to everybody in advance!

    • usernameOP
      link
      fedilink
      64 days ago

      Thanks! Cool video, I like her style. (Will look into the specifics of ed25519 out of interest when I have time… So, most probably not and I’ll just use it ;-D)

      • @[email protected]
        link
        fedilink
        33 days ago

        RSA4096 has a bit of an edge over ed25519 both in effective key size as well as support by things like YubiKeys and other HSMs that is beneficial for GPG but not really helpful for SSH.

  • @[email protected]
    link
    fedilink
    23 days ago

    SSH generally best to use ed25519, for GPG RSA4096 is better supported by HSMs and slightly more secure for longer-lived keys like root keys.

  • tla
    link
    13 days ago

    Others have provided the answer but if you want to explore system wide crypto policies check out update-crypto-policies

  • @JubilantJaguar
    link
    -23 days ago

    The correct answer to this question should be ''Whatever is the current default".

    If we have to ask and answer such questions as this (I’m unconvinced), then something is really wrong.