Internet Engineering Task Force (IETF) L. Velvindron Request for Comments: 8270 Hackers.mu Updates: 4419 M. Baushke Category: Standards Track Juniper Networks, Inc. ISSN: 2070-1721 December 2017Increase the Secure Shell Minimum Recommended Diffie-Hellman Modulus Size to 2048 Bits
Velvindron & Baushke Standards Track [Page 1]
RFC 8270 Recommended Minimum Modulus Size December 2017
Copyright Notice
1. Introduction
[RFC4419] specifies a recommended minimum DH modulus group size of 1024 bits. It also suggests that in all cases, the size of the group needs to be at least 1024 bits. This document updates [RFC4419] so that the minimum recommended size is 2048 bits. This recommendation is based on recent research [LOGJAM] on DH group weaknesses. This minimum DH group size may need to be increased to 3072 for forward- looking users.
2. Requirements Language
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here.
Velvindron & Baushke Standards Track [Page 2]
RFC 8270 Recommended Minimum Modulus Size December 2017 3. 2048-Bit DH GroupRecent research [LOGJAM] strongly suggests that DH groups that are 1024 bits can be broken by state-sponsored actors and any organization with enough computing resources. The authors show how they are able to break 768-bit DH groups and extrapolate the attack to 1024-bit DH groups. In their analysis, they show that breaking 1024 bits can be done with sufficient computing resources. This document provides the following recommendation: SSH servers and SSH clients SHOULD support groups with a minimum acceptable group size of 2048 bits for the "min" value of the SSH_MSG_KEY_DH_GEX_REQUEST client message given in [RFC4419]. Further, SSH clients SHOULD be able to send a value of 3072 bits for the preferred acceptable group size "n" in the SSH_MSG_KEY_DH_GEX_REQUEST message.
4. Interoperability
This document keeps the following requirement from [RFC4419]:
Velvindron & Baushke Standards Track [Page 3]
RFC 8270 Recommended Minimum Modulus Size December 2017 5. Security ConsiderationsThis document discusses security issues of DH groups that are 1024 bits in size, and formally updates the minimum size of DH groups to be 2048 bits. A hostile or "owned" SSH server implementation could potentially use backdoored DH primes using the methods described in [Backdoor-DH] to provide the g and p values to be used. Or, it could just send the calculated secret through a covert channel of some sort to a passive listener.
6. IANA Considerations
This document does not require any IANA actions.7. References 7.1. Normative References[RFC2119] Bradner, S., "Key words for use in RFCs to Indicate
7.2. Informative References
[Backdoor-DH]
Velvindron & Baushke Standards Track [Page 4]
RFC 8270 Recommended Minimum Modulus Size December 2017
[LOGJAM] Adrian, D., Bhargavan, K., Durumeric, Z., Gaudry, P.,