Factoring Legacy RSA Public Keys of a 1990s Certificate Authority
Researcher M. Pherrin has successfully executed the factorization of the RSA public keys belonging to a legacy Certificate Authority (CA) operating in the 1990s. By utilizing the General Number Field Sieve (GNFS) algorithm—likely via the CADO-NFS implementation—the researcher recovered the private prime factors (p, q) from the CA's public modulus (n). This achievement demonstrates that legacy RSA bit-lengths, previously considered computationally secure, are now susceptible to modern distributed computing resources. The successful factorization highlights a critical risk in Public Key Infrastructure (PKI) environments where antiquated root certificates or legacy-supported domains may still reside in trust stores, potentially allowing for the unauthorized issuance of forged X.509 certificates.
-
Research Overview: Cryptographic Degradation
- Analyzes the practical erosion of RSA security through the lens of legacy PKI.
- Demonstrates the transition of specific bit-lengths from "computationally secure" to "trivial" via modern compute.
- Focuses on the lifecycle of cryptographic primitives within long-lived organizational infrastructures.
-
Methodology: GNFS Factorization Mechanics
- Leverages the General Number Field Sieve (GNFS) to decompose the targeted public modulus.
- Targets legacy X.509 certificate chains originating from the 1990s.
- Utilizes modern distributed computing resource logs (CPU/GPU hours) to achieve factorization.
- Recovers specific prime factors (p, q) required to reconstruct the private key.
-
Technical Impact: PKI Integrity Loss
- Confirms the total compromise of the targeted CA's identity and signing capabilities.
- Highlights the danger of "lingering trust" in legacy root certificates within modern client trust stores.
- Establishes the potential for attackers to forge certificates for legacy-supported domains or services.
- Compares 1990s-era computational constraints against 2026-era factorization capabilities.
-
Industry Implications: The Agility Requirement
- Underscores the critical necessity for organizations to maintain cryptographic agility.
- Illustrates why bit-length migration (e.g., to RSA-3072 or ECC) is a mandatory lifecycle task.
- Warns against the systemic risk of maintaining hardcoded trust in outdated cryptographic standards.
-
Defensive Outlook: Trust Store Hygiene
- Mandates comprehensive audits of existing trust stores to identify deprecated or low-strength legacy roots.
- Recommends enforcing strict minimum bit-length requirements for all PKI deployments.
- Advocates for the accelerated transition to post-quantum or higher-entropy classical algorithms.
Related posts
- news.ycombinator.com — I've factored the RSA keys of a Certificate Authority from the 90s
- News
- Schneier
- Redhat
- Media
- Khoury
- Researchgate
- Smartfacts
- Cse
- En
- Crypto