← Back to Daily Briefing (#PKI)

Factoring Legacy RSA Public Keys of a 1990s Certificate Authority

Published September 9, 2026

Researcher M. Pherrin has successfully executed the factorization of the RSA public keys belonging to a legacy Certificate Authority (CA) operating in the 1990s. By utilizing the General Number Field Sieve (GNFS) algorithm—likely via the CADO-NFS implementation—the researcher recovered the private prime factors (p, q) from the CA's public modulus (n). This achievement demonstrates that legacy RSA bit-lengths, previously considered computationally secure, are now susceptible to modern distributed computing resources. The successful factorization highlights a critical risk in Public Key Infrastructure (PKI) environments where antiquated root certificates or legacy-supported domains may still reside in trust stores, potentially allowing for the unauthorized issuance of forged X.509 certificates.

  • Research Overview: Cryptographic Degradation

    • Analyzes the practical erosion of RSA security through the lens of legacy PKI.
    • Demonstrates the transition of specific bit-lengths from "computationally secure" to "trivial" via modern compute.
    • Focuses on the lifecycle of cryptographic primitives within long-lived organizational infrastructures.
  • Methodology: GNFS Factorization Mechanics

    • Leverages the General Number Field Sieve (GNFS) to decompose the targeted public modulus.
    • Targets legacy X.509 certificate chains originating from the 1990s.
    • Utilizes modern distributed computing resource logs (CPU/GPU hours) to achieve factorization.
    • Recovers specific prime factors (p, q) required to reconstruct the private key.
  • Technical Impact: PKI Integrity Loss

    • Confirms the total compromise of the targeted CA's identity and signing capabilities.
    • Highlights the danger of "lingering trust" in legacy root certificates within modern client trust stores.
    • Establishes the potential for attackers to forge certificates for legacy-supported domains or services.
    • Compares 1990s-era computational constraints against 2026-era factorization capabilities.
  • Industry Implications: The Agility Requirement

    • Underscores the critical necessity for organizations to maintain cryptographic agility.
    • Illustrates why bit-length migration (e.g., to RSA-3072 or ECC) is a mandatory lifecycle task.
    • Warns against the systemic risk of maintaining hardcoded trust in outdated cryptographic standards.
  • Defensive Outlook: Trust Store Hygiene

    • Mandates comprehensive audits of existing trust stores to identify deprecated or low-strength legacy roots.
    • Recommends enforcing strict minimum bit-length requirements for all PKI deployments.
    • Advocates for the accelerated transition to post-quantum or higher-entropy classical algorithms.

Related posts

  1. news.ycombinator.com — I've factored the RSA keys of a Certificate Authority from the 90s
  2. News
  3. Schneier
  4. Redhat
  5. Media
  6. Khoury
  7. Researchgate
  8. Smartfacts
  9. Cse
  10. En
  11. Crypto

LINK COPIED TO CLIPBOARD