We would like to migrate to a stronger key sizes, RSA 4096-bit, for the Trusted Root and Intermediate CAs to ensure they remain secure throughout their lifecycle for Endevor Web products. Is it support?
Because Endevor Web Services, Bridge for Git (B4G), and the Web UI run on the Java Runtime Environment (JRE)/Tomcat, Endevor Web products inherit the cryptographic capabilities of the underlying Java version. Modern Java versions, supported by Endevor (Java 21 and higher) support 4096-bit RSA keys, therefore the Endevor Web products support 4096-bit RSA keys.
Note: For older runtimes (like Java 8, 11, or 17), you may encounter known TLS/SSL handshake limitations or certificate validation errors with 4096-bit keys.
All three ESMs(ACF2, Top Secret and RACF) support Keysize 4096.