I\'m in the process of creating a CSR, and I wonder which is arguably the best length for my RSA key.
Of course, 384 is probably too weak, and 16384 is probably too
Certificate authorities will not sign csrs less than 2048 bits in size so you should generate your csr to be 2048 bits.
I think 4096 is ok for RSA
Check This link
The end of the SHA-1 signature is nothing new, but Google has accelerated the process of the chrome. In the next few weeks, you should check their SSL certificates.
This may be helpful