• Home
  • Podcast
  • Contact
Ervik.as
Cloud, Cyber Security, EUC, DaaS and HCI
  • Cloud
    • Azure
    • Citrix Cloud
    • Cloud Management
    • Nutanix Clusters
  • Cyber Security
    • Arctic Wolf
    • Cyber Security News
  • EUC
    • Citrix
      • Citrix Analytics
      • Citrix NetScaler
      • Citrix Provisioning
      • Receiver
      • ShareFile
      • Citrix Virtual Apps (XenApp)
      • Citrix Virtual Desktops (XenDesktop)
      • Workspace
      • Workspace app
    • DaaS
      • Azure Virtual Desktop
      • Frame
    • Microsoft
      • HoloLens
      • Microsoft App-V
      • Remote Desktop Services
      • Windows 7
      • Windows 8
      • Windows 10
      • Windows Server 2008
      • Windows Server 2008 R2
      • Windows Server 2012
      • Windows Server 2012 R2
      • Windows Server 2016
    • Thin Clients
      • Igel
      • Wyse
    • VMware
      • Fusion
      • Horizon View
      • Vmware ThinApp
      • Vmware Workstation
    • Parallels
      • Remote Application Server
  • End User Experience
    • ControlUp
    • eG Innovations
    • Goliath Technologies
    • Liquidware
  • Datacenter
    • Backup & Disaster Recovery
      • Altaro
      • HYCU
      • Unitrends
      • Rubrik
      • Veeam Software
    • Containers
      • Docker
      • Red Hat OpenShift
    • Hybrid Multi Cloud
      • Nutanix
        • Nutanix Database Service
        • Files
        • Flow
        • Nutanix AHV
        • Nutanix Cloud Platform
    • Server Virtualization
      • Nutanix AHV
      • Microsoft Hyper-V
      • VMware vSphere
      • Citrix Hypervisor (XenServer)
    • Network & Security
      • Nutanix Flow
      • Palo Alto Networks
  • About
    • Cookie Policy (EU)
    • News
      • Citrix Community News

NetScaler

How Citrix NetScaler Makes it Easy to Comply Now with Next Year’s NIST Requirement to Migrate to 2048-bit RSA Keys

Alexander Ervik Johnsen 2048-bit RSA keys, Citrix, NetScaler, NetScaler MPX, NIST, RSA 2010-07-22

Robert Chen, Principal Product Marketing Manager, NetScaler » Citrix announced it has enhanced its NetScaler MPX product to offer easy adoption of 2048-bit RSA key requirements as recommended by the National Institute of Standards and Technology (NIST).  Citrix talks about why the company is leading the industry as the first to adapt its networking technology in anticipation of this necessary customer migration.

Q: Why is the industry moving to 2048-bit RSA keys?
A: National Institute of Standards and Technology (NIST) issued Special Publication 800-57 in March 2007, which recommends the use of 2048-bit RSA keys starting Jan. 1, 2011. Federal agencies are required to comply with NIST recommendations. NIST recommendations are also generally adopted by private enterprises and other foreign countries. To ease the transition from 1024-bit RSA-keys to 2048-bit RSA keys, NIST issued Draft SP 800-131 in June 2010, which extends the deadline to move to 2048-bit RSA keys to 2013. Specifically, Draft SP 800-131 states:

 

  • 2048-bit RSA keys: “Acceptable” – meaning the algorithm and key length is safe to use; no security risk is currently known.
  • 1024-bit RSA keys: “Deprecated from 2011 – 2013” – meaning the use of the algorithm and key length is allowed, but the user must accept some risk.

Q: What does the NIST publications mean for customers?
A: Customers will need to replace their 1024-bit certificates with 2048-bit certificates. Federal, financial services and healthcare industries will likely be the first ones to adopt 2048-bit certificates due to regulatory standards, with other industries following closely behind.

Q: What has Citrix done with its NetScaler product to lessen the impact of moving to 2048-bit keys?
A: We leveraged our multi-core, nCore architecture and recent SSL enhancements, and we partnered with Cavium to optimize the performance of NetScaler for 2048-bit SSL keys. As a result, we were able to increase our performance for 2048-bit SSL keys by 5X.

Q: How are certificate authorities (e.g., Verisign, Entrust, RSA, etc.) responding to this change?
A: Verisign and other CAs are converting their root certificate servers to 2048-bit RSA keys beginning Q4’2010. CAs will default to issuing new certificates in 2048-bit key sizes. Requests for 1024-bit certificates will be treated as “exceptions” and set to expire at the end of 2013.

Q: How will 2048-bit RSA keys affect SSL performance?
A: SSL with 2048-bit RSA keys require significantly greater processing capacity – up to 30x more. This means that to equal the SSL TPS performance of a single ADC for 1024-bit keys requires up to 30 equivalent ADCs.

Source

Related Posts

NetScaler /

DoS and RCE Vulnerabilities Exploited in Citrix NetScaler ADC and NetScaler Gateway multiple CVE´s

NetScaler /

Citrix NetScaler is back

NetScaler /

Citrix and FireEye Mandiant Launch Indicator of Compromise Scanner

NetScaler /

Permanent fixes for CVE-2019-19781 – Vulnerability for Citrix ADC versions 11.1 and 12.0

NetScaler /

CVE-2019-19781 – Vulnerability in Citrix Application Delivery Controller and Citrix Gateway

‹ A collection of Microsoft Hyper-V Tools› Citrix NetScaler Boosts SSL Performance 5X to Meet the Demands of New Security Standards

Back to Top

Crafted in the land of the Vikings 🇳🇴 by Alexander Ervik Johnsen.
Copyright 2000-2025 - www.ervik.as - All Rights Reserved