# Bug: Alpine certbot package (docker) generates Private-Key: (256 bit)

**URL:** <https://community.letsencrypt.org/t/bug-alpine-certbot-package-docker-generates-private-key-256-bit/225381>\
**Category:** Help\
**Created:** [September 9, 2024, 5:07pm UTC](https://community.letsencrypt.org/t/bug-alpine-certbot-package-docker-generates-private-key-256-bit/225381 "2024-09-09T17:07:44Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![lordspace](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/lordspace/32/6596_2.png) [@lordspace](https://community.letsencrypt.org/u/lordspace)\
**Post date:** [September 9, 2024, 5:07pm UTC](https://community.letsencrypt.org/t/bug-alpine-certbot-package-docker-generates-private-key-256-bit/225381/1 "2024-09-09T17:07:44Z")

</div>

For some odd reason the cli ignored the specified key length and nginx won't load the cert.

My domain is: clients-eu.devel.ca

I ran this command (shortened as I call the temp container):  
certbot   
certonly   
--webroot   
--webroot-path /var/www/html   
--noninteractive --verbose --rsa-key-size 4096   
--email [admin+apps+clients@orbisius.com](mailto:admin+apps+clients@orbisius.com)   
--verbose --text --agree-tos   
-d clients-eu.devel.ca   
-d www.clients-eu.devel.ca 2\>&1 \

It produced this output:  
all was successfully issued.

My web server is (include version):  
nginx. v1.26.0

The operating system my web server runs on is (include version):  
Ubuntu 22

My hosting provider, if applicable, is:  
contabo

I can login to a root shell on my machine (yes or no, or I don't know):  
yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):  
no

The version of my client is  
certbot 2.10.0

---

<div class="post-metadata">

**Author:** ![lordspace](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/lordspace/32/6596_2.png) [@lordspace](https://community.letsencrypt.org/u/lordspace)\
**Post date:** [September 9, 2024, 5:10pm UTC](https://community.letsencrypt.org/t/bug-alpine-certbot-package-docker-generates-private-key-256-bit/225381/2 "2024-09-09T17:10:11Z")

</div>

I revoked the SSL cert and then requested a new one and have the same problem

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [September 9, 2024, 5:13pm UTC](https://community.letsencrypt.org/t/bug-alpine-certbot-package-docker-generates-private-key-256-bit/225381/3 "2024-09-09T17:13:16Z")

</div>

Hi @lordspace,

Certbot changed to default [ECDSA certificates by default and other upcoming changes in Certbot 2.0](https://community.letsencrypt.org/t/ecdsa-certificates-by-default-and-other-upcoming-changes-in-certbot-2-0/177013) and [Existing RSA key/cert renewed as ECDSA on Certbot upgrade - #7 by \_az](https://community.letsencrypt.org/t/existing-rsa-key-cert-renewed-as-ecdsa-on-certbot-upgrade/195317/7)

If you want RSA I believe you still need one more option set see [User Guide — Certbot 2.11.0 documentation](https://eff-certbot.readthedocs.io/en/stable/using.html#rsa-and-ecdsa-keys)

---

<div class="post-metadata">

**Author:** ![lordspace](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/lordspace/32/6596_2.png) [@lordspace](https://community.letsencrypt.org/u/lordspace)\
**Post date:** [September 9, 2024, 5:16pm UTC](https://community.letsencrypt.org/t/bug-alpine-certbot-package-docker-generates-private-key-256-bit/225381/4 "2024-09-09T17:16:46Z")

</div>

Thanks for the quick reply!  
If I omit the key size would it fix this?

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [September 9, 2024, 5:17pm UTC](https://community.letsencrypt.org/t/bug-alpine-certbot-package-docker-generates-private-key-256-bit/225381/5 "2024-09-09T17:17:24Z")

</div>

I believe to keep RSA you likely want to add the option `--key-type rsa`

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [September 9, 2024, 5:28pm UTC](https://community.letsencrypt.org/t/bug-alpine-certbot-package-docker-generates-private-key-256-bit/225381/6 "2024-09-09T17:28:52Z")

</div>

Indeed. Just specifying the key size without telling Certbot which type you want isn't enough.

One could think: "Hey, but if I mention `--rsa-key-size` on the command line, that would imply using RSA, right?" Well, I guess, but Certbot isn't that smart..

> [@lordspace](#):
>
> I revoked the SSL cert (…)

Revoking isn't really necessary unless the private key got leaked.

---

<div class="post-metadata">

**Author:** ![lordspace](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/lordspace/32/6596_2.png) [@lordspace](https://community.letsencrypt.org/u/lordspace)\
**Post date:** [September 9, 2024, 6:28pm UTC](https://community.letsencrypt.org/t/bug-alpine-certbot-package-docker-generates-private-key-256-bit/225381/7 "2024-09-09T18:28:24Z")

</div>

That command line with `--rsa-key-size` used to work perfectly for the last 4-6 years. Would certbot upgrade the key to 4096?

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [September 9, 2024, 6:30pm UTC](https://community.letsencrypt.org/t/bug-alpine-certbot-package-docker-generates-private-key-256-bit/225381/8 "2024-09-09T18:30:37Z")

</div>

Certbot changed the default key type to ECDSA with Certbot v2.0.0. And in between 2.0.0 and 2.somewhat there was a bug that it did not detect properly if an already existing certificate was RSA and simply used ECDSA without the user knowing.

---

<div class="post-metadata">

**Author:** ![lordspace](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/lordspace/32/6596_2.png) [@lordspace](https://community.letsencrypt.org/u/lordspace)\
**Post date:** [September 9, 2024, 6:32pm UTC](https://community.letsencrypt.org/t/bug-alpine-certbot-package-docker-generates-private-key-256-bit/225381/9 "2024-09-09T18:32:16Z")

</div>

It's a brand new certificate for a new staging site

---

<div class="post-metadata">

**Author:** ![lordspace](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/lordspace/32/6596_2.png) [@lordspace](https://community.letsencrypt.org/u/lordspace)\
**Post date:** [September 9, 2024, 6:40pm UTC](https://community.letsencrypt.org/t/bug-alpine-certbot-package-docker-generates-private-key-256-bit/225381/10 "2024-09-09T18:40:02Z")

</div>

I tried `certbot renew --key-type ecdsa --cert-name example.com --force-renewal`  
from the docs: [User Guide — Certbot 2.11.0 documentation](https://eff-certbot.readthedocs.io/en/stable/using.html#rsa-and-ecdsa-keys)

The private key is super short 241 bytes! my other key is 1.7K.

I think certbot should be smart to auto detect the type based on the key size parameter if key type wasn't passed. I can't believe nobody thought of that.

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [September 9, 2024, 6:42pm UTC](https://community.letsencrypt.org/t/bug-alpine-certbot-package-docker-generates-private-key-256-bit/225381/11 "2024-09-09T18:42:20Z")

</div>

ECSDA private keys and certificates are substantially shorter than their RSA counterparts.

---

<div class="post-metadata">

**Author:** ![petercooperjr](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/petercooperjr/32/84698_2.png) [@petercooperjr](https://community.letsencrypt.org/u/petercooperjr)\
**Post date:** [September 9, 2024, 6:43pm UTC](https://community.letsencrypt.org/t/bug-alpine-certbot-package-docker-generates-private-key-256-bit/225381/12 "2024-09-09T18:43:08Z")

</div>

Yeah, certbot assumes that if you care about the key type at all, then you'd pass the key type argument. It probably _should_ warn if you pass an RSA key size when you're not using an RSA key, but really it's uncommon that one _needs_ an RSA key nowadays. As you've noticed, ECDSA keys are much smaller.

---

<div class="post-metadata">

**Author:** ![lordspace](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/lordspace/32/6596_2.png) [@lordspace](https://community.letsencrypt.org/u/lordspace)\
**Post date:** [September 9, 2024, 6:51pm UTC](https://community.letsencrypt.org/t/bug-alpine-certbot-package-docker-generates-private-key-256-bit/225381/13 "2024-09-09T18:51:53Z")

</div>

I would probably care but I have scripts and tools that automatically generate certificates.  
Thank you all for helping me and answering my questions!

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [September 9, 2024, 7:03pm UTC](https://community.letsencrypt.org/t/bug-alpine-certbot-package-docker-generates-private-key-256-bit/225381/14 "2024-09-09T19:03:12Z")

</div>

> [@lordspace](#):
>
> The private key is super short 241 bytes! my other key is 1.7K.

I'm not really following. Is your complaint that your private key is small or that you're getting ECDSA certificates instead of RSA?

What did you expect when you typed `--key-type ecdsa`? An RSA key type somehow?

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [October 9, 2024, 7:03pm UTC](https://community.letsencrypt.org/t/bug-alpine-certbot-package-docker-generates-private-key-256-bit/225381/15 "2024-10-09T19:03:47Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
