CA API Gateway: RSASSA-PKCS1-v1_5 not recommended

Document ID : KB000111569
Last Modified Date : 17/08/2018
Show Technical Document Details
Question:

In the GUI and documentation for the 'Encode Json Web Token' assertion, it is noted that

"CA Technologies strongly recommends using HMAC or ECDSA algorithms whenever possible. Use the RSASSA algorithms only when absolutely necessary for interoperability"

Why is RSASSA not recommended?

Answer:
Security considerations are the reason RSASSA-PKCS1-v1_5 algorithms are labelled as 'not recommended' in our GUI and documentation.

From the RFC section-3.3, "A key of size 2048 bits or larger MUST be used with these algorithms.".  Since the key/key-size is also chosen by the user, we wanted to bring attention to the importance of the setting without limiting their ability to choose it. 

 
Additional Information:
https://tools.ietf.org/html/rfc7518#section-3
https://tools.ietf.org/html/rfc7518#section-3.3