All fixes

Upgrade a short TLS private key

tls-key-size

Your certificate key is below the current 2048-bit floor. Reissue with a 2048-bit RSA key or an ECDSA P-256 key, then retire the old one.

Why this matters

Your encryption key is shorter than recommended. Theoretically crackable with significant resources, but not realistically exploitable — no attacker is brute-forcing RSA keys for a targeted MitM.

Nginx

  1. 1 Generate a new key with at least 2048-bit RSA (or use ECDSA P-256)
  2. 2 Re-issue your certificate with the new key
bash
# Generate a 4096-bit RSA key
openssl genrsa -out server.key 4096

# Or use ECDSA (faster, smaller, equally secure)
openssl ecparam -genkey -name prime256v1 -out server.key

Does your app still have this?

Scan your domain