Repository navigation
Pkcs12 keyloading check - #5925
Open
falko-strenzke wants to merge 1 commit into
Open
falko-strenzke wants to merge 1 commit into
falko-strenzke wants to merge 1 commit into
Conversation
Owner
|
Needs a squash and a more clear commit message. Test inputs should be pregenerated and stored in |
falko-strenzke
force-pushed
the
pkcs12-keyloading-check
branch
from
September 8, 2026 06:46
433a734 to
bfbc8c9
Compare
Collaborator
Author
All addressed now. The commit message reads: |
falko-strenzke
force-pushed
the
pkcs12-keyloading-check
branch
3 times, most recently
from
September 11, 2026 10:52
77c6abc to
71409a5
Compare
The MAC in a PKCS#12 file is optional, and the PBE schemes used for PKCS8ShroudedKeyBag and EncryptedData provide no authentication of their own. In a file without a MAC, or with a MAC computed under a password the attacker knows, the CBC encrypted private key is malleable. A modification that lands inside the private scalar of an EC key yields a key that still decodes, still carries the original public point (which the EC PKCS#8 decoder takes verbatim), still matches the end-entity certificate, and signs without any error, producing signatures that verify under neither the certificate nor the key's own public point. The parser now runs Private_Key::check_key (non-strong) on every key loaded from a KeyBag or PKCS8ShroudedKeyBag and rejects the file with a Decoding_Error if the check fails. No RNG is available in the parser, so a Null_RNG is passed; the non-strong checks of EC, RSA and DL keys need no randomness (primality testing falls back to a deterministic method when the RNG is unseeded). Key types whose check requires randomness, such as ML-KEM, raise PRNG_Unseeded, which is caught so that such keys continue to load unchecked. For RSA the corruption was already caught at signing time by the CRT consistency check in the private operation; the new check moves the failure to import time and reports it as a decoding error rather than an Internal_Error on first use. Tests use pregenerated inputs under src/tests/data/pkcs12: OpenSSL generated P-256 and RSA-2048 keys whose PKCS#8 encoding was modified (foreign public point, respectively flipped bit in dP), exported with "openssl pkcs12 -export" in PBES2, PBE-SHA1-3DES and unencrypted KeyBag form, plus a consistent MAC-less file for a bit-flip regression sweep and two Botan generated ML-KEM-512 bundles covering the fallback path. The generation procedure is documented in the test source.
falko-strenzke
force-pushed
the
pkcs12-keyloading-check
branch
from
September 11, 2026 11:02
71409a5 to
38ab995
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.