All Products 
Username / Customer#
Password
Log In
  • Site Search
  • Domain Search
  • WHOIS Domain Check
24/7 Support: (480) 505-8877
Hablamos Español
9 AM to 9 PM IST
7 days a week
Go Daddy Support

Search help articles, forums, and discussion groups

Why does my CSR need to be 2048 bit length?

Date Submitted: 5-9-2012

Computer power has lessened the time it takes to break the algorithms used by today's secure certificate private keys.

To avoid putting the Internet and e-commerce users at risk, the Certificate Authority Browser Forum has published new requirements for secure certificates. We are a member of this organization and are supporting this change by requiring 2048-bit length for all new and renewing SSLs.

The following are the requirements established by the Certificate Authority Browser Forum for Extended Validation Certificates:

  • A minimum of 2048-bit RSA keys for root and subordinate CAs.
  • A minimum of 2048-bit keys for entity certificates (the secure certificates issued to our customers) that expire after December 31st, 2010.

Microsoft®, for example, is a member of the Certificate Authority Browser Forum and supports these requirements for all certificates by incorporating the following requirements into their programs:

  • All new root certificates must have a minimum of 2048-bit RSA keys.
  • 1024-bit roots will be removed from the Microsoft Root Certificate Program by December 13th, 2013.
  • All end entity certificates issued after December 31st, 2010 must have a minimum of 2048-bit RSA keys.

Use our CSR Generation instructions if you are having difficulty generating a 2048-bit CSR.

Rate This Article:

Have a question about the content of this article?