# Private key size \> 4096 - strange error message

**URL:** <https://community.letsencrypt.org/t/private-key-size-4096-strange-error-message/8396>\
**Category:** Issuance Tech\
**Created:** [January 6, 2016, 10:10pm UTC](https://community.letsencrypt.org/t/private-key-size-4096-strange-error-message/8396 "2016-01-06T22:10:55Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![lgromanowski](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/lgromanowski/32/2857_2.png) [@lgromanowski](https://community.letsencrypt.org/u/lgromanowski)\
**Post date:** [January 6, 2016, 10:10pm UTC](https://community.letsencrypt.org/t/private-key-size-4096-strange-error-message/8396/1 "2016-01-06T22:10:55Z")

</div>

Hi,  
does [letsencrypt.org](http://letsencrypt.org) server has any restrictions for private key size?

One of [letsencrypt\_plugin](https://github.com/lgromanowski/letsencrypt-plugin/issues/12) users has a problem with key size = 8192. I can reproduce this error with a private key generated in following way: `openssl genrsa 8192 > key/keyfile.pem` sever responds with an error: “Acme::Client::Error::Unauthorized: No registration exists matching provided key”. Is it correct behavior?

---

<div class="post-metadata">

**Author:** ![tlussnig](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/tlussnig/32/2053_2.png) [@tlussnig](https://community.letsencrypt.org/u/tlussnig)\
**Post date:** [January 6, 2016, 10:45pm UTC](https://community.letsencrypt.org/t/private-key-size-4096-strange-error-message/8396/2 "2016-01-06T22:45:14Z")

</div>

Yes there is an restriction to 4096 you can find the restrictions in

> <https://github.com/letsencrypt/boulder/blob/79fa5eed000af2ff34e3d90f87a77fef10fb0132/core/good_key.go>

  
Line 74  
Minimum size is 2048 and Maximum Size is 4096 and also some quality checks on the key.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [January 6, 2016, 10:59pm UTC](https://community.letsencrypt.org/t/private-key-size-4096-strange-error-message/8396/3 "2016-01-06T22:59:57Z")

</div>

Does anyone know **why** Let’s Encrypt has such upper limits to the RSA key size?

The CA/Browser Forum only mentions minimum key sizes in its [Baseline Requirements](https://cabforum.org/wp-content/uploads/Baseline_Requirements_V1_3_1.pdf).

Performance perhaps? Signing a bigger key puts a heavier burden on the signing process?

---

<div class="post-metadata">

**Author:** ![tlussnig](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/tlussnig/32/2053_2.png) [@tlussnig](https://community.letsencrypt.org/u/tlussnig)\
**Post date:** [January 6, 2016, 11:17pm UTC](https://community.letsencrypt.org/t/private-key-size-4096-strange-error-message/8396/4 "2016-01-06T23:17:52Z")

</div>

Hi, signing bigger keys is no performance issue. Because for signing you first calculate the SHA256 hash and  
the sign it with the CA Private RSA key.  
The heavier burden is when you use the large RSA key for key exchange/signing in tls as server.  
I think it is the same as the limit to only two EC curves the \*\*\* argument that it is not widely supported.

---

<div class="post-metadata">

**Author:** ![lgromanowski](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/lgromanowski/32/2857_2.png) [@lgromanowski](https://community.letsencrypt.org/u/lgromanowski)\
**Post date:** [January 6, 2016, 11:33pm UTC](https://community.letsencrypt.org/t/private-key-size-4096-strange-error-message/8396/5 "2016-01-06T23:33:04Z")

</div>

Thanks for information! 🙂

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [January 6, 2016, 11:35pm UTC](https://community.letsencrypt.org/t/private-key-size-4096-strange-error-message/8396/6 "2016-01-06T23:35:17Z")

</div>

Well, the modulus of a large RSA key is a vey big part of the certificate, right? And you can’t deny that calculating the SHA256 hash of a bigger piece of data costs more CPU power than a smaller piece of data, right? 😉

But you’re right, that probably won’t be a very big performance penalty indeed. 🙂 Your argument is more likely I’m afraid.

[offtopic] Did you know in elliptic curve ciphers, the _verification_ part is relatively heavy performance-wise compared to signing? In the end EC ciphers are still a better choice compared to RSA, but for a client a RSA key is easy peasy while a large EC curve verification is _relative_ heavy.

---

<div class="post-metadata">

**Author:** ![tlussnig](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/tlussnig/32/2053_2.png) [@tlussnig](https://community.letsencrypt.org/u/tlussnig)\
**Post date:** [January 6, 2016, 11:48pm UTC](https://community.letsencrypt.org/t/private-key-size-4096-strange-error-message/8396/7 "2016-01-06T23:48:16Z")

</div>

1. SHA256 is done as you said in the CPU in this case it is the server cpu. This mean it can be delegated to multiple server. But the “expensive” part is the signing of the hash done by HSM module.
2. Large key require more space in the CT servers and for OCSP and is expensive on mobile devices.
3. ECDSA the signing is in the prime field is depending on the optimisation maximum about twice as fast as verification.

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [January 8, 2016, 8:15pm UTC](https://community.letsencrypt.org/t/private-key-size-4096-strange-error-message/8396/8 "2016-01-08T20:15:53Z")

</div>

Performance and size.
