Skip to content

Derive PBES2 and DEK-Info keys from the passphrase's UTF-8 octets - #205

Merged
Xor-el merged 1 commit into
masterfrom
pbe-utf8-passphrase
Sep 29, 2026
Merged

Xor-el merged 1 commit into
masterfrom
pbe-utf8-passphrase

Conversation

@Xor-el

@Xor-el Xor-el commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Encrypted PKCS#8 (PBES2/PBKDF2) and legacy DEK-Info PEM keys derived their key from the passphrase's
single-byte/ANSI code-page bytes instead of its UTF-8 octets, so a non-ASCII passphrase disagreed with
OpenSSL and BouncyCastle (and could collapse to '?' for characters outside the active code page).

This routes the PBES2 and DEK-Info password->bytes through the existing Pkcs5PasswordToUtf8Bytes,
matching OpenSSL's UTF-8 passphrase convention (RFC 8018 3). PKCS#12 (BMPString via
Pkcs12PasswordToBytes) and the PKCS#5 v1 schemes are deliberately unchanged; ASCII passphrases are
byte-identical across ANSI/Latin-1/UTF-8, so all existing vectors are unaffected.

Adds two non-ASCII passphrase regression tests (a PBES2 AES-256-CBC PKCS#8 key and a DEK-Info
AES-256-CBC PEM key) with OpenSSL-generated vectors; these fail on Windows before the change and pass
after. Note: a PBES2/DEK-Info blob previously written with a non-ASCII passphrase on Windows was
ACP-derived and will no longer open with the same passphrase (it never opened in OpenSSL/BC either).

Gate: FPC console suite x86_64 + i386 and Delphi Win32 all green (1579 tests).

Encrypted PKCS#8 (PBES2/PBKDF2) and legacy DEK-Info PEM keys derived their key from the passphrase's
single-byte/ANSI code-page bytes, so a non-ASCII passphrase disagreed with OpenSSL and BouncyCastle
(and could collapse to '?' outside the active code page). Route those two derivations through the
existing Pkcs5PasswordToUtf8Bytes, matching OpenSSL's UTF-8 passphrase convention (RFC 8018 3). PKCS#12
(BMPString) and the PKCS#5 v1 schemes are unchanged, and ASCII passphrases are byte-identical, so every
existing vector is unaffected. Adds non-ASCII passphrase tests for a PBES2 AES-256-CBC key and a
DEK-Info AES-256-CBC PEM key.
@Xor-el
Xor-el merged commit 2781a78 into master Sep 29, 2026
28 checks passed
@Xor-el
Xor-el deleted the pbe-utf8-passphrase branch September 29, 2026 03:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant