Closed Bug 1373716 Opened 9 years ago Closed 5 years ago

Import of PKCS#12 files with Camellia encryption is not supported

Categories

(NSS :: Libraries, defect, P3)

3.28.2
defect

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: hkario, Assigned: rrelyea)

References

Details

Attachments

(1 file)

Description of problem: PKCS#12 files encrypted using camellia-128-cbc, camellia-192-cbc or camellia-256-cbc algorithms are unsupported by pk12util How reproducible: Always Steps to Reproduce: 1. openssl req -x509 -newkey rsa -keyout localhost.key -out localhost.crt -subj /CN=localhost -nodes -batch 2. echo "RedHatEnterpriseLinux7.1" | openssl pkcs12 -export -out bundle.p12 -in localhost.crt -caname server-cert -nokeys -passout stdin -certpbe camellia-128-cbc -keypbe camellia-128-cbc 3. pk12util -l bundle.p12 -W RedHatEnterpriseLinux7.1 -v Actual results: pk12util: PKCS12 decode not verified: SEC_ERROR_BAD_DER: security library: improperly formatted DER-encoded message. pk12util: PKCS12 decode not verified: SEC_ERROR_BAD_DER: security library: improperly formatted DER-encoded message. Expected results: Contents of the PKCS#12 file listed Additional info: Import of the PKCS#12 file to the NSS database does not work either.
Priority: -- → P3
with the 3.31 changes, it seems like the camellia-256-cbc got fixed for key storage unfortunately the two other are still broken, and neither works for certificate storage
Assignee: nobody → rrelyea
Status: NEW → ASSIGNED

Bug 1707130 Fixed the base issue with Camellia, but now it has the same issue
as AES did which was fixed in Bug 1268141.

The fix is to generalize the AES patch, recognizing the issue isn't AES
specific but an issue for any case where we encode the keysize into the
oid, but the oid maps to the same PKCS #11 mechanism.

This patch condenses a lot of the original AES fix, collecting several blocks
of common code into single functions, and putting one place where the key
sizes of pkcs5v2 algorithms with different oids with keys size specific
to those oids, but their mechanism maps to a single PKCS #11 mechanism
live. This means future algorithms can be handled easily.

bob

Patch has been applied.

Status: ASSIGNED → RESOLVED
Closed: 5 years ago
Resolution: --- → FIXED
Blocks: 452464
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: