Closed
Bug 1373716
Opened 9 years ago
Closed 5 years ago
Import of PKCS#12 files with Camellia encryption is not supported
Categories
(NSS :: Libraries, defect, P3)
Tracking
(Not tracked)
RESOLVED
FIXED
3.71
People
(Reporter: hkario, Assigned: rrelyea)
References
Details
Attachments
(1 file)
Description of problem:
PKCS#12 files encrypted using camellia-128-cbc, camellia-192-cbc or camellia-256-cbc algorithms are unsupported by pk12util
How reproducible:
Always
Steps to Reproduce:
1. openssl req -x509 -newkey rsa -keyout localhost.key -out localhost.crt -subj /CN=localhost -nodes -batch
2. echo "RedHatEnterpriseLinux7.1" | openssl pkcs12 -export -out bundle.p12 -in localhost.crt -caname server-cert -nokeys -passout stdin -certpbe camellia-128-cbc -keypbe camellia-128-cbc
3. pk12util -l bundle.p12 -W RedHatEnterpriseLinux7.1 -v
Actual results:
pk12util: PKCS12 decode not verified: SEC_ERROR_BAD_DER: security library: improperly formatted DER-encoded message.
pk12util: PKCS12 decode not verified: SEC_ERROR_BAD_DER: security library: improperly formatted DER-encoded message.
Expected results:
Contents of the PKCS#12 file listed
Additional info:
Import of the PKCS#12 file to the NSS database does not work either.
Updated•9 years ago
|
Priority: -- → P3
| Reporter | ||
Comment 1•9 years ago
|
||
with the 3.31 changes, it seems like the camellia-256-cbc got fixed for key storage
unfortunately the two other are still broken, and neither works for certificate storage
| Assignee | ||
Updated•5 years ago
|
Assignee: nobody → rrelyea
Status: NEW → ASSIGNED
| Assignee | ||
Comment 3•5 years ago
|
||
Bug 1707130 Fixed the base issue with Camellia, but now it has the same issue
as AES did which was fixed in Bug 1268141.
The fix is to generalize the AES patch, recognizing the issue isn't AES
specific but an issue for any case where we encode the keysize into the
oid, but the oid maps to the same PKCS #11 mechanism.
This patch condenses a lot of the original AES fix, collecting several blocks
of common code into single functions, and putting one place where the key
sizes of pkcs5v2 algorithms with different oids with keys size specific
to those oids, but their mechanism maps to a single PKCS #11 mechanism
live. This means future algorithms can be handled easily.
bob
| Assignee | ||
Comment 4•5 years ago
|
||
Patch has been applied.
Status: ASSIGNED → RESOLVED
Closed: 5 years ago
Resolution: --- → FIXED
Comment 5•5 years ago
|
||
Target Milestone: --- → 3.71
You need to log in
before you can comment on or make changes to this bug.
Description
•