From ef6a17d4a6cd8cf8361088c43e343f5cc7cbf985 Mon Sep 17 00:00:00 2001 From: PortableTech Date: Wed, 24 Jun 2015 18:49:19 -0400 Subject: [PATCH] Increase DKIM key length to 2048 Currently MiaB creates 1024 bit keys which is seen as a minimum standard by several providers such as Google who already uses a 2048 bit key. Increasing the keysize beyond 2048 is an issue as it often goes beyond supported DNS record sizes. --- setup/dkim.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/setup/dkim.sh b/setup/dkim.sh index 56d5c3fc..956f425c 100755 --- a/setup/dkim.sh +++ b/setup/dkim.sh @@ -41,7 +41,7 @@ fi # entry which we'll want to include in our DNS setup. if [ ! -f "$STORAGE_ROOT/mail/dkim/mail.private" ]; then # Should we specify -h rsa-sha256? - opendkim-genkey -r -s mail -D $STORAGE_ROOT/mail/dkim + opendkim-genkey -b 2048 -r -s mail -D $STORAGE_ROOT/mail/dkim fi # Ensure files are owned by the opendkim user and are private otherwise.