Cryptographic Key Length Distribution
Our scanning telemetry analyzed the public key sizes used in leaf certificates:
- RSA 2048-bit: 68% of certificates.
- ECDSA 256-bit: 27% of certificates.
- RSA 4096-bit: 5% of certificates.
Defensive Policy Guidelines
To mitigate downgrade threats, security teams should immediately enforce TLS 1.2 as the minimum protocol version and disable all CBC-mode ciphers in web-facing server blocks. Ensure HSTS is enabled with a minimum duration of one year.