Q: Maximum keysizes supported for CA certificates? (RSA and EC)
Hi,
a customer plans to build a new PKI to last for the next decade (at least), and they plan to create CA certificates (root and intermediates) with very long RSA keys (8192 and 16384 bit!).
Since these CAs are planned to be used to issue VPN Server certificates as well as client (identity) Certificates, the FortiGate and FortiManager here will have to be able to use those CA certificates (to be more specific: their 8192 and 16384 bit long RSA public keys) to verifiy that Client and Server certificates are signed by those CAs.
Is that supported? What are the limits for RSA keys and EC curves for certificate validations (in user authentication, VPN IKE authentication etc.)
Please note that we do not plan to generate certificate requests with FortiGates or FortiManager that have more than 4096 bit RSA keys, but they will have to be able to verify signatures made by those CAs.
At the moment there is nothing implemented, so we cannot test it out.
