SECURING


History of supported key sizes in Notes and Domino

Understand the RSA key sizes supported by Notes and Domino from past releases to the current release.

Matrix of RSA key sizes supported by Notes and Domino
Hierarchical IDsHierarchical IDsFlat IDsFlat IDs
VersionActionDomesticInternationalDomesticInternational
R8 - R12accept8192/4096(*)512630512
R8 - R12generate4096/2048(*)51200
R7accept2048512630512
R7generate102451200
R6accept1024512630512
R6, R5generate63051200
R5, V4accept760(*)512630512
V4generate630512630512
V3accept760/630(*)512630512
V3generate512512512380
V2.1accept00512512
V2.1generate00512380
V2, V1accept00512380
V2, V1generate00512380

* RSA Keys over 630 bits must be BER-formatted.


Key sizes supported by feature

Bulk data key sizes:


Document Encryption Key (NEK) sizes:
Ticket (network authentication) sizes:
Session key (network encryption) sizes:
Password-derived keys (ID file encryption keys):
Local database encryption:

This feature was added in V4.1. Four variations of local database encryption exist:


Weak and medium database encryption have been deprecated and are not available for use with new databases.

S/MIME


TLS

Support for SSLv3 has been removed. Only TLS 1.2 is enabled out of the box. Forward Secrecy using NIST P-256, NIST P-384, and NIST P-521 was added in 9.0.1 FP4 IF2. Forward Secrecy using X25519 and X448 was added in 12.0.


Credentials for TLS
Transport Layer Security (TLS) v1.2 via IBM HTTP Server

This feature was added in 9.0 and was never subject to export restrictions. Requires selecting "IBM HTTP Server" install-time option Supports ciphers that use AES and SHA-2.

The "IBM HTTP Server" install option was removed in Domino 10.0.

ID file recovery

This feature was added in R5 and was never subject to export restrictions. ID file recovery uses 1024 bit RSA asymmetric keys.


Notes ID vault

This feature was added in 8.5 and was never subject to export restrictions.


Security Assertion Markup Language (SAML) service provider

This feature was added in 9.0 and was never subject to export restrictions.

Supported DigestMethod algorithms:


Supported SignatureMethod algorithms:
Supported EncryptionMethod (bulk) algorithms:
Supported EncryptionMethod (wrapping) algorithms:
Exclusive canonicalization (xml-exc-c14n) should be used; #WithComments or inclusive canonicalization (REC-xml-c14n) may not parse successfully. Parent topic: Securing

Related concepts
The evolution of Notes RSA key sizes