Derive PBES2 and DEK-Info keys from the passphrase's UTF-8 octets - #205
Merged
Merged
Conversation
Encrypted PKCS#8 (PBES2/PBKDF2) and legacy DEK-Info PEM keys derived their key from the passphrase's single-byte/ANSI code-page bytes, so a non-ASCII passphrase disagreed with OpenSSL and BouncyCastle (and could collapse to '?' outside the active code page). Route those two derivations through the existing Pkcs5PasswordToUtf8Bytes, matching OpenSSL's UTF-8 passphrase convention (RFC 8018 3). PKCS#12 (BMPString) and the PKCS#5 v1 schemes are unchanged, and ASCII passphrases are byte-identical, so every existing vector is unaffected. Adds non-ASCII passphrase tests for a PBES2 AES-256-CBC key and a DEK-Info AES-256-CBC PEM key.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Encrypted PKCS#8 (PBES2/PBKDF2) and legacy DEK-Info PEM keys derived their key from the passphrase's
single-byte/ANSI code-page bytes instead of its UTF-8 octets, so a non-ASCII passphrase disagreed with
OpenSSL and BouncyCastle (and could collapse to '?' for characters outside the active code page).
This routes the PBES2 and DEK-Info password->bytes through the existing
Pkcs5PasswordToUtf8Bytes,matching OpenSSL's UTF-8 passphrase convention (RFC 8018 3). PKCS#12 (BMPString via
Pkcs12PasswordToBytes) and the PKCS#5 v1 schemes are deliberately unchanged; ASCII passphrases arebyte-identical across ANSI/Latin-1/UTF-8, so all existing vectors are unaffected.
Adds two non-ASCII passphrase regression tests (a PBES2 AES-256-CBC PKCS#8 key and a DEK-Info
AES-256-CBC PEM key) with OpenSSL-generated vectors; these fail on Windows before the change and pass
after. Note: a PBES2/DEK-Info blob previously written with a non-ASCII passphrase on Windows was
ACP-derived and will no longer open with the same passphrase (it never opened in OpenSSL/BC either).
Gate: FPC console suite x86_64 + i386 and Delphi Win32 all green (1579 tests).