Upgrade a short TLS private key
tls-key-size
Your certificate key is below the current 2048-bit floor. Reissue with a 2048-bit RSA key or an ECDSA P-256 key, then retire the old one.
Why this matters
Your encryption key is shorter than recommended. Theoretically crackable with significant resources, but not realistically exploitable — no attacker is brute-forcing RSA keys for a targeted MitM.
Web servers
Nginx
- 1 Generate a new key with at least 2048-bit RSA (or use ECDSA P-256)
- 2 Re-issue your certificate with the new key
bash
# Generate a 4096-bit RSA key
openssl genrsa -out server.key 4096
# Or use ECDSA (faster, smaller, equally secure)
openssl ecparam -genkey -name prime256v1 -out server.keyDoes your app still have this?
Scan your domain