ALERT: Some images may not load properly within the Knowledge Base Article. If you see a broken image, please right-click and select 'Open image in a new tab'. We apologize for this inconvenience.

CA API Gateway: RSASSA-PKCS1-v1_5 not recommended


Article ID: 111569


Updated On:


STARTER PACK-7 CA Rapid App Security CA API Gateway


In the GUI and documentation for the 'Encode Json Web Token' assertion, it is noted that

"CA Technologies strongly recommends using HMAC or ECDSA algorithms whenever possible. Use the RSASSA algorithms only when absolutely necessary for interoperability"

Why is RSASSA not recommended?


Component: APIESM


Security considerations are the reason RSASSA-PKCS1-v1_5 algorithms are labelled as 'not recommended' in our GUI and documentation.

From the RFC section-3.3, "A key of size 2048 bits or larger MUST be used with these algorithms.".  Since the key/key-size is also chosen by the user, we wanted to bring attention to the importance of the setting without limiting their ability to choose it. 


Additional Information