> Source: [sk96591](https://support.checkpoint.com/results/sk/sk96591)

# sk96591 - RSA Key Lengths in Check Point Products

| Property | Value |
|----------|-------|
| Solution ID | sk96591 |
| Date Created | 2013-11-28 |
| Last Modified | 2025-11-16 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R82, R81.20, R81.10 (EOS), R82, R81.20, R81 (EOS), R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Solution

**Table of Contents:**

* Overview
* Internal CA (Root) Certificate
* SIC Certificate
* User Certificate, Client Certificate
* Gaia Portal Certificate
* HTTPS Portals (Multi-Portal) Certificate, VPN Certificate
* Endpoint Certificate
* RSA Key Lengths for SSH

<br />

Click Here to Show the Entire Article

<br />

Overview {#Overview}
--------------------

> This article outlines the lengths of RSA keys used in various Check Point products and instructs how to modify the default key length.
>
> **Notes:**
>
> * The default key length of RSA keys generated by Check Point Internal CA is 2048-bit. You can see this information in the ICA portal in the section "Configure the CA".
> * On a Multi-Domain Security Management Server:
>   * This configuration applies only in the Domain Management Server context, in which you configure these settings.
>   * You can configure these settings also in the "MDS" context (and they do not apply to the existing or new Domain Management Servers).

Internal CA (Root) Certificate {#ICA}
-------------------------------------

Show / Hide this section  
> Impact on the Environment and Warnings:
>
> * This procedure deletes and creates again the Internal CA on the Management Server.
> * This procedure deletes all certificates from the Management Server.  
>   You must generate and distribute all the certificates again.  
>   You must establish SIC again with all managed Security Gateways / Cluster Members.
>
> Therefore:
>
> * Consult Check Point Support before recreating the CA.
> * Test this in a controlled lab first.
> * Make sure you have a good backup (including a Gaia Snapshot) for the Management Server.
> * Perform this procedure during a downtime.
>
> Supported RSA key lengths:
>
> |------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
> | Key Length | Availability                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
> | 1024 bits  | Included starting from the version R60                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
> | 2048 bits  | Included starting from the version R75                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
> | 3072 bits  | Included starting from (PMTR-86409): * [Check Point R81.20](https://support.checkpoint.com/results/sk/sk173903) * [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 82 * [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 77 * [Jumbo Hotfix Accumulator for R80.40](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) starting from Take 190 |
> | 4096 bits  | Included starting from the version R75                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
>
> Procedure to change the RSA key length for ICA certificate on the Management Server:
>
> 1. Collect a full backup of the Management Server:
>
>    1. Collect the backup of the management database (with the "`migrate_server export`" / "`mds_backup`" command).  
>       See the [Command Line Interface (CLI) Reference Guide](https://support.checkpoint.com/product/184#f[commonsource]=C.%20Documentation) for your version.
>
>    2. Take a Gaia snapshot.  
>       See the [Gaia Administration Guide](https://support.checkpoint.com/product/184#f[commonsource]=C.%20Documentation) for your version.
>
> 2. Connect to the command line on the Management Server.
>
> 3. Log in to the Expert mode.
>
> 4. On a Multi-Domain Security Management Server, go to the context of the applicable Domain Management Server:
>
>    **`mdsenv <IP Address or Name of Domain Management Server>`**
> 5. Back up the current *$FWDIR/conf/InternalCA.C* file:
>
>    **`cp -v $FWDIR/conf/InternalCA.C{,_ORIGINAL}`**
> 6. Edit the current *$FWDIR/conf/InternalCA.C* file:
>
>    **`vi $FWDIR/conf/InternalCA.C`**
> 7. Below the line "**serial_num_of_digits**", add these two lines:
>
>    **Note**: Make sure to add a horizontal TAB before each line and a single space between the parameter name and its value in parentheses.
>
>    **`:ica_key_size (<KEY_LENGTH>)`**
>
>    **`:sic_key_size (<KEY_LENGTH>)`**
>
>    Example for 3072 bits:
>
>    ```
>    (
>            :mgmt_tools_web_gui (1)
>            :mgmt_tools_admin_list (
>            )
>            :mgmt_tools_user_list (
>            )
>            :crl_duration (604800)
>            :authorization_code_length (6)
>            :serial_num_of_digits (5)
>            :ica_key_size (3072)
>            :sic_key_size (3072)
>    )
>    ```
>
> 8. Save the changes in the file and exit Vi editor.
>
> 9. Reset SIC as described in:
>
>    [sk14532 - "fwm sic_reset" command on Security Management fails with "There are IKE Certificates that were generated by the internal Certificate Authority](https://support.checkpoint.com/results/sk/sk14532)"

SIC Certificate {#SIC}
----------------------

Show / Hide this section  
> Supported RSA key lengths:
>
> |------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
> | Key Length | Availability                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
> | 1024 bits  | Included starting from the version R60                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
> | 2048 bits  | Included starting from the version R75                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
> | 3072 bits  | Included starting from (PMTR-86409): * [Check Point R81.20](https://support.checkpoint.com/results/sk/sk173903) * [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 82 * [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 77 * [Jumbo Hotfix Accumulator for R80.40](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) starting from Take 190 |
> | 4096 bits  | Included starting from the version R75                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
>
> Procedure to change the RSA key length for SIC certificates on the Management Server:
>
> 1. Collect a full backup of the Management Server:
>
>    1. Collect the backup of the management database (with the "`migrate_server export`" / "`mds_backup`" command).  
>       See the [Command Line Interface (CLI) Reference Guide](https://support.checkpoint.com/product/184#f[commonsource]=C.%20Documentation) for your version.
>
>    2. Take a Gaia snapshot.  
>       See the [Gaia Administration Guide](https://support.checkpoint.com/product/184#f[commonsource]=C.%20Documentation) for your version.
>
> 2. Connect to the Internal CA Management Tool on Security Management Server / Domain Management Server.
>
>    For more information about the ICA Management Tool, see [sk30501 - Setting up the ICA Management Tool](https://support.checkpoint.com/results/sk/sk30501).
> 3. Change the SIC key size:
>
>    1. In the upper left menu, go to **Configure the CA**.
>
>    2. Go to the **Key Size Attributes** section.
>
>    3. In the **SIC key size** field, enter the desired value - **1024** , **2048** , **3072** , or **4096**.
>
>    4. At the top of the page, click the **Apply** button.
>
> 4. Reset and stablish SIC again with all managed Security Gateways / Cluster Members as described in:
>
>    [sk65764 - How to reset SIC](https://support.checkpoint.com/results/sk/sk65764).

User Certificate, Client Certificate {#VPN_User_Client}
-------------------------------------------------------

Show / Hide this section  
> 1. Collect a full backup of the Management Server:
>
>    1. Collect the backup of the management database (with the "`migrate_server export`" / "`mds_backup`" command).  
>       See the [Command Line Interface (CLI) Reference Guide](https://support.checkpoint.com/product/184#f[commonsource]=C.%20Documentation) for your version.
>
>    2. Take a Gaia snapshot.  
>       See the [Gaia Administration Guide](https://support.checkpoint.com/product/184#f[commonsource]=C.%20Documentation) for your version.
>
> 2. Connect to the Internal CA Management Tool on Security Management Server / Domain Management Server.
>
>    For more information about the ICA Management Tool, see [sk30501 - Setting up the ICA Management Tool](https://support.checkpoint.com/results/sk/sk30501).
> 3. Change the User / Client Certificate key size:
>
>    1. In the upper left menu, go to **Configure the CA**.
>
>    2. Go to the **Key Size Attributes** section.
>
>    3. In the **User Certificate key size** field, enter the desired value - **1024** , **2048** , or **4096**.
>
>    4. At the top of the page, click the **Apply** button.
>
> 4. Generate the User / Client Certificate again.

Gaia Portal Certificate {#Gaia_Portal}
--------------------------------------

Show / Hide this section  
> 1. Take a Gaia snapshot on the Gaia Server.  
>    See the [Gaia Administration Guide](https://support.checkpoint.com/product/184#f[commonsource]=C.%20Documentation) for your version.
>
> 2. Connect to the command line on the Gaia server.
>
> 3. Log in to the Expert mode.
>
> 4. Stop the Apache HTTPD2 process:
>
>    **tellpm process:httpd2**
> 5. Back up the current */web/conf/server.key* file:
>
>    **cp -v /web/conf/server.key{,_ORIGINAL}**
> 6. Back up the current */web/conf/server.crt* file:
>
>    **`cp -v /web/conf/server.crt{,_ORIGINAL}`**
> 7. Remove the current */web/conf/server.key* file:
>
>    **rm -i /web/conf/server.key**
> 8. Remove the current */web/conf/server.crt* file:
>
>    **rm -i /web/conf/server.crt**
> 9. Generate the Certificate Signing Request with the required RSA key length - **1024** , **2048** , or **4096** bits.
>
>    Example for 4096 bits:
>
>    **`cpopenssl req -new -x509 -sha256 -days 3652 -newkey rsa:4096 -nodes -keyout /web/conf/server.key -out /web/conf/server.crt -config $CPDIR/conf/openssl.cnf`**
> 10. Start the Apache HTTPD2 process:
>
>     **`tellpm process:httpd2 t`**

HTTPS Portals (Multi-Portal) Certificate, VPN Certificate {#MultiPortal}
------------------------------------------------------------------------

Show / Hide this section  
> This section applies to:
>
> * A certificate for various portals on the Security Gateway - Mobile Access Portal, Identity Awareness Portal, Data Loss Prevention Portal, UserCheck Portal.
> * A VPN Certificate.
>
> Supported RSA key lengths:
>
> |------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
> | Key Length | Availability                                                                                                                                                                                                                                                                                            |
> | 1024 bits  | Included starting from the version R60                                                                                                                                                                                                                                                                  |
> | 2048 bits  | Included starting from the version R75                                                                                                                                                                                                                                                                  |
> | 3072 bits  | Included starting from (PMTR-94089): * [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 70 * [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 152 |
> | 4096 bits  | Included starting from the version R75                                                                                                                                                                                                                                                                  |
>
> <br />
>
> Procedure:  
>
> 1. Collect a full backup of the Management Server:
>
>    1. Collect the backup of the management database (with the "`migrate_server export`" / "`mds_backup`" command).  
>       See the [Command Line Interface (CLI) Reference Guide](https://support.checkpoint.com/product/184#f[commonsource]=C.%20Documentation) for your version.
>
>    2. Take a Gaia snapshot.  
>       See the [Gaia Administration Guide](https://support.checkpoint.com/product/184#f[commonsource]=C.%20Documentation) for your version.
>
> 2. Connect with SmartConsole to the Security Management Server / Domain Management Server.
>
> 3. In the top left corner, click **Menu** \> **Global properties**.
>
> 4. In the left panel, click the **Advanced** page.
>
> 5. Click the **Configure** button.
>
> 6. In the left panel, click the **Certificates and PKI properties** page.
>
> 7. Find this option: **host_certs_key_size**.
>
> 8. Click the drop-down and select the desired key size: **1024** , **2048** , **3072** or **4096**.
>
> 9. Click **OK** to close the **Advanced Configuration** window.
>
> 10. Click **OK** to close the **Global Properties** window.
>
> 11. Publish the session.
>
> 12. Follow [sk31539](https://support.checkpoint.com/results/sk/sk31539) to renew the default certificate.
>
> 13. Generate the VPN Certificate again.
>
> 14. Install the Access Control Policy on the Security Gateways / Clusters / VSX Virtual Systems.

Endpoint Certificate {#Endpoint}
--------------------------------

Show / Hide this section  
> Renewal of the Management Server SIC certificate will automatically renew the Endpoint certificate.

RSA Key Lengths for SSH {#SSH}
------------------------------

Show / Hide this section  
> Summary:
>
> |---------|------------------------|
> | Version | RSA Key Length for SSH |
> | R82.10  | 3072                   |
> | R82     | 2048                   |
> | R81.20  | 2048                   |
> | R81.10  | 2048                   |
> | R81     | 2048                   |
>
> Procedure:
>
> 1. Connect to the command line on a Gaia OS server.
> 2. Log in.
> 3. If the default shell is Gaia Clish, go to the Expert mode:  
>    `expert`
> 4. Run this command and refer to the leftmost column:  
>    `ssh-keygen -lf /etc/ssh/ssh_host_rsa_key`  
>    To see the length of all SSH keys, run:  
>    `for KEY in $(grep ssh_host /etc/ssh/sshd_config | awk '{print $2}') ; do ssh-keygen -lf ${KEY} ; done`

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
