Skip to content

Commit a882114

Browse files
Update updating-certificates.md
1 parent a2c77f8 commit a882114

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

content/operate/rs/security/certificates/updating-certificates.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -141,3 +141,9 @@ To update your syncer certificate on clusters running Active-Active databases, f
141141
- Run step 2 as quickly as possible after step 1. Between the two steps, new syncer connections that use the ‘old’ certificate will get rejected by the cluster that has been updated with the new certificate (in step 1).<br/>
142142
- Do not run any other `crdb-cli crdb update` operations between the two steps.<br/>
143143
{{</note>}}
144+
145+
### Troubleshoot RHEL 8 crypto policy and certificate key size
146+
147+
In RHEL 8, if the crypto policy is set to `FUTURE`, the system will not accept certificates with private key sizes smaller than 3072 bits. This affects the use of custom certificates with smaller keys (such as 2048-bit keys).
148+
149+
To use certificates with smaller key sizes, you need to change the crypto policy from `FUTURE` to `DEFAULT`. For more information about crypto policies, see the [Red Hat documentation on system-wide cryptographic policies](https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/security_hardening/using-the-system-wide-cryptographic-policies_security-hardening).

0 commit comments

Comments
 (0)