I've factored the RSA keys of a Certificate Authority from the 90s
I’ve factored the RSA keys of a Certificate Authority... … from the 90s. I’ve been thinking about the security of RSA lately. RSA’s cryptography relies on the difficulty of factoring a large semiprime number, but what “large” means is an interesting question. The Web PKI deprecated 1024-bit RSA over a decade ago, and while I don’t know of anyone factoring a key of that size, it’s within the realm of possibility for a government or other organization with a large number of computers. Just a few days ago, someone factored the 862-bit RSA-260 key from the RSA factoring challenge. That’s the largest factorization I’m aware of. Today, the world uses RSA of at least 2048 bits, but even that will be deprecated soon with the risk of quantum computers in the future. This led me to wonder: small RSA keys can be factored on even a modest desktop computer. And in the early days of the Web PKI, there were no standards, and no minimum requirements. Netscape shipped SSL support in 1994, and IE shortly afterwards. This was still the era of export restrictions on cryptography. Are there any keys small enough that I can factor? I don’t have any good reason to do that, but it seems like fun. The spoiler is of course, yes, but first we need to find a key to crack. Fortunately, root certificates were shipped with browser installers, and there are archives of both Internet Explorer and Netscape on archive.org. The archives aren’t comprehensive, but they should provide good coverage of old root CAs. I downloaded both collections and set Claude Code on extracting all the roots. I’ve hosted a Claude-generated webpage with all those old-timey, ancient roots. While I haven’t verified this LLM output is entirely trustworthy, it looks pretty plausible. Using the filters on that site, we can find what small keys are trusted for SSL. Aha! We have a target. Back in March 1999, Netscape 4.51 shipped a 512-bit RSA certificate authority trusted for SSL, and another for S/MIME. These two roots were both from the long-defunct Canadian certificate authority called E-Certify. Later that year, the 512-bit RSA-155 was factored, so even in its era this was too weak and probably shouldn’t have shipped in the first place. The E-Certify 512-bit roots were removed by Netscape in 2002. Unfortunately, Internet Explorer seems to have never shipped any 512-bit roots for SSL, so our fun will be limited to Netscape from a relatively small time frame. Factoring the public keys in the root certificates will give me the two primes that I need to reconstruct the private key. I ran CADO-NFS on my Ryzen 9 5950X desktop; it took 32 hours to factor E-Certify RSA 512 Gold Server for SSL, and another 29 hours for E-Certify RSA 512 Gold Client for S/MIME. You can get the resulting private keys below. Assuming you’re somehow running Netscape 4.51 with a clock set before E-Certify roots expired on 2003-10-16, you can use these private keys to issue certificates. This describes zero people on the planet… except for this VM I set up. Verifying that the issued certificates would work in Netscape 4.51 was an adventure in itself, as there is zero overlap in TLS capability between Netscape 4.51 and any modern TLS stack. So it was back to Claude Code to make a custom old-timey TLS server in Go. This site is publicly hosted at e-certify.fly.dev, which you are welcome to try out with your own copy of Netscape, but it won’t load in any modern browser. Or, if you’d like to host your own website using these old-timey keys, the keys and tools are all in the repo at https://github.com/mcpherrinm/ancientroots. Or do worse, like MitM the SSL of all those Netscape 4.51 users with their clocks set to 25 years ago… C=CA, O=E-Certify, OU=RSA Gold Server, CN=E-Certify RSA 512 Gold Server -----BEGIN CERTIFICATE----- MIIByjCCAXSgAwIBAgIBATANBgkqhkiG9w0BAQQFADBjMQswCQYDVQQGEwJDQTES MBAGA1UEChMJRS1DZXJ0aWZ5MRgwFgYDVQQLEw9SU0EgR29sZCBTZXJ2ZXIxJjAk BgNVBAMTHUUtQ2VydGlmeSBSU0EgNTEyIEdvbGQgU2VydmVyMB4XDTk4MTAxNjEz Mzc1M1oXDTAzMTAxNjEzMzc1M1owYzELMAkGA1UEBhMCQ0ExEjAQBgNVBAoTCUUt Q2VydGlmeTEYMBYGA1UECxMPUlNBIEdvbGQgU2VydmVyMSYwJAYDVQQDEx1FLUNl cnRpZnkgUlNBIDUxMiBHb2xkIFNlcnZlcjBcMA0GCSqGSIb3DQEBAQUAA0sAMEgC QQDNVQ93Ev7zgNaJAR1Z7gCydU6mky1e/B4EbY1NsdtfsitU9cELqg5uRJDPA40n CDPeOyil1lJ5N8hekcqJAkkXAgMBAAGjEzARMA8GA1UdEwEB/wQFMAMBAf8wDQYJ KoZIhvcNAQEEBQADQQB09SV6OeeDEP8Je3DOLNZ24U98NHqIBTDyB4sRpDmNdHum +3rm4AYtznBxG5hEShO89bcWi3yJtBITGuTRDnMq -----END CERTIFICATE----- -----BEGIN RSA PRIVATE KEY----- MIIBOgIBAAJBAM1VD3cS/vOA1okBHVnuALJ1TqaTLV78HgRtjU2x21+yK1T1wQuq Dm5EkM8DjScIM947KKXWUnk3yF6RyokCSRcCAwEAAQJAWZ2FOWf+A9K4T2VAJS69 +SU/pW3YwHrysuYJZN56K0Iz+Hqd1hBhCeJ3/T+/cvXq+ctD0x3uOxU1rDSeCoMO KQIhAPdbc1wTm3twWDYi1iXmRBXz97MYxRFld/KFr8x5+tK9AiEA1IG09a+oVg6j NMDj6GD7spaD4q9t1wk/Nyq/MTLPkmMCIEzzYjvuzZvlI0wUIlLAA8Zgk1pgBk6X Jm2IMVyHRgRxAiEAjZKgCTHuVu7HgiSjcTPzW0X1NTckWSc66zjaSR+Ns/sCICxT yXoTXWQCWL6BMpf2no7IlvoEnBIrED2Frq3PxlEA -----END RSA PRIVATE KEY----- C=CA, O=E-Certify, OU=RSA Gold Client, CN=E-Certify RSA 512 Gold Client -----BEGIN CERTIFICATE----- MIIByjCCAXSgAwIBAgIBAjANBgkqhkiG9w0BAQQFADBjMQswCQYDVQQGEwJDQTES MBAGA1UEChMJRS1DZXJ0aWZ5MRgwFgYDVQQLEw9SU0EgR29sZCBDbGllbnQxJjAk BgNVBAMTHUUtQ2VydGlmeSBSU0EgNTEyIEdvbGQgQ2xpZW50MB4XDTk4MTAxNjEz MzQwOFoXDTAzMTAxNjEzMzQwOFowYzELMAkGA1UEBhMCQ0ExEjAQBgNVBAoTCUUt Q2VydGlmeTEYMBYGA1UECxMPUlNBIEdvbGQgQ2xpZW50MSYwJAYDVQQDEx1FLUNl cnRpZnkgUlNBIDUxMiBHb2xkIENsaWVudDBcMA0GCSqGSIb3DQEBAQUAA0sAMEgC QQBwCcT1iYlNyKPywB/kffD8esiCzGYJxSnTXQjU6ej/XxnA+9yqjzAMPtqFd094 wM89Vsmz9YOWSO6Qn6wOAs45AgMBAAGjEzARMA8GA1UdEwEB/wQFMAMBAf8wDQYJ KoZIhvcNAQEEBQADQQAdktdM5AzW+0o96eHCHwD3UfzxPvjKxPEjiI/QTn+njHt/ BEJb9yZatONRckglVc9v8P8Dy8HZGQD0+Pn0uxhW -----END CERTIFICATE----- -----BEGIN RSA PRIVATE KEY----- MIIBOQIBAAJAcAnE9YmJTcij8sAf5H3w/HrIgsxmCcUp010I1Ono/18ZwPvcqo8w DD7ahXdPeMDPPVbJs/WDlkjukJ+sDgLOOQIDAQABAkASXZeaxFPsm0I8zb+snfR9 /saVolnrqhVEH5EODdXy3nSm6fpdrsDwQDDg52biXjIUizQYdd3OourOn0/PyyiB AiEAyW4gFFgM0dJ+Y//vrIyQutLeH/5c/Vq3Lbcxv7R908kCIQCOZAAv8OCG/2oH yKaYj/EoxcFZ9csVh/kjicO/JIX+8QIhAMEzAkvhBDLALYAmvDCJBkxa8rhHFdPf jbCodGwGZ2WZAiB//XmBnlZkYl/PoVfGmNRgHun+0AZ9UxzqCeJvBQiBMQIgHWlr 0Sh1a8K2pQP2ktgmL3RH5+1Qd2wLx/hhGWtwPvU= -----END RSA PRIVATE KEY----- As a bonus, Internet Explorer 3.02 shipped a code signing CA called OU=Test VeriSign Commercial Software Publisher CA. I’m not sure what that’s for, but it’s just as easily factored. There are a few other test-looking 512-bit RSA keys in the ancient roots repo, so you should try factoring some more of them, or seeing what they could be used for! L=Internet, O=VeriSign, Inc., OU=Test VeriSign Commercial Software Publisher CA -----BEGIN CERTIFICATE----- MIIByDCCAXKgAwIBAgIQIsTi2AgEp+1OkpqVLROnazANBgkqhkiG9w0BAQQFADBl MREwDwYDVQQHEwhJbnRlcm5ldDEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xNzA1 BgNVBAsTLlRlc3QgVmVyaVNpZ24gQ29tbWVyY2lhbCBTb2Z0d2FyZSBQdWJsaXNo ZXIgQ0EwHhcNOTYwNTAyMTcwMTUyWhcNOTcwNTAyMTcwMTUyWjBlMREwDwYDVQQH EwhJbnRlcm5ldDEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xNzA1BgNVBAsTLlRl c3QgVmVyaVNpZ24gQ29tbWVyY2lhbCBTb2Z0d2FyZSBQdWJsaXNoZXIgQ0EwXDAN BgkqhkiG9w0BAQEFAANLADBIAkEA1XqTpg1hQWq6IKvBXLor12GBTH6y4BHyOJjy MJISn0ZWBqkbZiEfoWgaWXhEwrvxMWonLA2vYFHijofFG4YIjwIDAQABMA0GCSqG SIb3DQEBBAUAA0EAKxuR/KPJPDNJgw0ORqqM7SlvIeqnVP71OEFytqPaZw/3TPEi 9oK6PzBvPdLBZlnjRd/hf58FW2+/PXxsFl78Mg== -----END CERTIFICATE----- -----BEGIN RSA PRIVATE KEY----- MIIBOwIBAAJBANV6k6YNYUFquiCrwVy6K9dhgUx+suAR8jiY8jCSEp9GVgapG2Yh H6FoGll4RMK78TFqJywNr2BR4o6HxRuGCI8CAwEAAQJAYM8tlegLarcToS1CiuKC bzHwiNgMFkENL01sx0n21/MhmA6pBiSwVn3Pu6yvx6EMB1zbCsaBHs/VTyofMbRW QQIhAOqdAX3bVZwAlZ5FDWyfGwgE0FXEIQ85kjcihrFeDs49AiEA6PBfC0YuNMSa M135mH+MEY1GEmQe9xHcXpiYAPazCrsCIQDDtuw6oJEfDYHCwRn8xhGXs+RT18Q4 Xi9yXRP9vFgfhQIhAIYUTfD0XYZcIBIvJosj56D2u328iaJXcow0s1Hirp4fAiAG bza0Qcc27d/0OzKOqep3JrDl/L5HidTj2XEqEXmnXw== -----END RSA PRIVATE KEY----- And finally, SSL Labs thinks my test site is great.