2019-11-10 18:43:15 -08:00
|
|
|
Bag Attributes
|
|
|
|
friendlyName: Minizip
|
|
|
|
localKeyID: 58 47 0B C9 69 23 3A 00 CD 7E 00 94 80 25 34 19 43 A8 C9 6C
|
Rewrite test certificates using more modern algorithms
The test.p12 file use the RC2-CBC and 3DES-CBC algorithms, which
are quite dated and require the `-legacy` option in openssl to read
them.
```console
$ openssl pkcs12 -in test.p12 -info -noout -legacy -passin pass:test
MAC: sha1, Iteration 1
MAC length: 20, salt length: 8
PKCS7 Encrypted data: pbeWithSHA1And40BitRC2-CBC, Iteration 2048
Certificate bag
PKCS7 Data
Shrouded Keybag: pbeWithSHA1And3-KeyTripleDES-CBC, Iteration 2048
```
Rewrite the test.p12 file with a current openssl (via p12 -> pem -> p12
conversion) to use more modern algorithms which do not require legacy
mode. Rewrite test.pem with a new export of test.p12.
```console
$ openssl pkcs12 -in test.p12 -info -noout -passin pass:test
MAC: sha256, Iteration 2048
MAC length: 32, salt length: 8
PKCS7 Encrypted data: PBES2, PBKDF2, AES-256-CBC, Iteration 2048, PRF hmacWithSHA256
Certificate bag
PKCS7 Data
Shrouded Keybag: PBES2, PBKDF2, AES-256-CBC, Iteration 2048, PRF hmacWithSHA256
```
2022-12-11 21:21:55 +01:00
|
|
|
subject=CN = Minizip, O = Minizip, OU = MZ, ST = AZ, C = US, L = Phoenix, emailAddress = nathan@nathanm.com
|
|
|
|
issuer=CN = Minizip, O = Minizip, OU = MZ, ST = AZ, C = US, L = Phoenix, emailAddress = nathan@nathanm.com
|
2019-11-10 18:43:15 -08:00
|
|
|
-----BEGIN CERTIFICATE-----
|
|
|
|
MIIDpzCCAo+gAwIBAgIBATANBgkqhkiG9w0BAQsFADCBgDEQMA4GA1UEAwwHTWlu
|
|
|
|
aXppcDEQMA4GA1UECgwHTWluaXppcDELMAkGA1UECwwCTVoxCzAJBgNVBAgMAkFa
|
|
|
|
MQswCQYDVQQGEwJVUzEQMA4GA1UEBwwHUGhvZW5peDEhMB8GCSqGSIb3DQEJARYS
|
|
|
|
bmF0aGFuQG5hdGhhbm0uY29tMB4XDTE5MTExMTAyMjYwMVoXDTM4MDIxMDAyMjYw
|
|
|
|
MVowgYAxEDAOBgNVBAMMB01pbml6aXAxEDAOBgNVBAoMB01pbml6aXAxCzAJBgNV
|
|
|
|
BAsMAk1aMQswCQYDVQQIDAJBWjELMAkGA1UEBhMCVVMxEDAOBgNVBAcMB1Bob2Vu
|
|
|
|
aXgxITAfBgkqhkiG9w0BCQEWEm5hdGhhbkBuYXRoYW5tLmNvbTCCASIwDQYJKoZI
|
|
|
|
hvcNAQEBBQADggEPADCCAQoCggEBAORnHpfjKNyRKiVoziTDXQAr5Bbaju33vhW6
|
|
|
|
RVK1mBbDWmDQUgRa/iHlpJMxeHOmAZOezeu+h9VWJ9Co1zMO7aoJfbvHk7iYTFBY
|
|
|
|
7lFpXi5xdMvSngmNq2+DGnAylwuPjmwFmbFftML/Fk/u5P/0KB4lxLY0n5pUppO6
|
|
|
|
sU4J6S1NjlNc19zW1fy2BXMibTxEFz9SMWCpKPy22JbBhzIWhzfQQlVHsQmx8yaR
|
|
|
|
LMLYGNurjZ8gJcObMQo7atN6IJb7rUSgTt2xLceL+aFGjb8dNap2fb/KsWNUR+OM
|
|
|
|
s8GVEjHoOrgu5xqGN2GVAeoccPyDySVk0B0nqJ1byDBoHli+fwMCAwEAAaMqMCgw
|
|
|
|
DgYDVR0PAQH/BAQDAgKEMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMDMA0GCSqGSIb3
|
|
|
|
DQEBCwUAA4IBAQBWcLT4hkSE1csTj2IhRvRoKX5eOz4g/GL4BbMsBmIYdTNcAT/M
|
|
|
|
NF5gIgeZRHJUiaaprTAawG6Kmbf9cUUSz04bWMitErJmYAPC9PmZhN501YzIsr8c
|
|
|
|
hks5+MCE0Z0P6STgor3hxGZ5RSuh6vCzKjgIONMXOevuBPCItJZmKIrOowHH/VvT
|
|
|
|
YUVcn3ZqBRPVOHeFuBugRyw8/RqpU/SpPb1Pupo9M7KVVNztpXMzfVV2tw2yNQiZ
|
|
|
|
7GSXKF65ukDfQ8t7+4cWbINmKpkDyA5Bg5lcQT3DpjKmiUTYGtqKU13m/OgbES9g
|
|
|
|
yampfcsNiorTiKw6JnSuwjv6VAZC+FZlz03b
|
|
|
|
-----END CERTIFICATE-----
|
|
|
|
Bag Attributes
|
|
|
|
friendlyName: Minizip
|
|
|
|
localKeyID: 58 47 0B C9 69 23 3A 00 CD 7E 00 94 80 25 34 19 43 A8 C9 6C
|
|
|
|
Key Attributes: <No Attributes>
|
|
|
|
-----BEGIN ENCRYPTED PRIVATE KEY-----
|
Rewrite test certificates using more modern algorithms
The test.p12 file use the RC2-CBC and 3DES-CBC algorithms, which
are quite dated and require the `-legacy` option in openssl to read
them.
```console
$ openssl pkcs12 -in test.p12 -info -noout -legacy -passin pass:test
MAC: sha1, Iteration 1
MAC length: 20, salt length: 8
PKCS7 Encrypted data: pbeWithSHA1And40BitRC2-CBC, Iteration 2048
Certificate bag
PKCS7 Data
Shrouded Keybag: pbeWithSHA1And3-KeyTripleDES-CBC, Iteration 2048
```
Rewrite the test.p12 file with a current openssl (via p12 -> pem -> p12
conversion) to use more modern algorithms which do not require legacy
mode. Rewrite test.pem with a new export of test.p12.
```console
$ openssl pkcs12 -in test.p12 -info -noout -passin pass:test
MAC: sha256, Iteration 2048
MAC length: 32, salt length: 8
PKCS7 Encrypted data: PBES2, PBKDF2, AES-256-CBC, Iteration 2048, PRF hmacWithSHA256
Certificate bag
PKCS7 Data
Shrouded Keybag: PBES2, PBKDF2, AES-256-CBC, Iteration 2048, PRF hmacWithSHA256
```
2022-12-11 21:21:55 +01:00
|
|
|
MIIFHDBOBgkqhkiG9w0BBQ0wQTApBgkqhkiG9w0BBQwwHAQIdEObza0X7HkCAggA
|
|
|
|
MAwGCCqGSIb3DQIJBQAwFAYIKoZIhvcNAwcECFaNr4AhZbmfBIIEyLxrF5LWO64O
|
|
|
|
iuhuUbPy7I7eXU3efFoWN5rUA++Ul+e8nSAbonTWTh1tedaKJCZAnG0AmJUR0c8A
|
|
|
|
f/88YsEETLAH9DhakmrRwfwbPugXXI030q9enAKswILwS856hu9RVEmAwwA4pnma
|
|
|
|
cWFWWdbk7urPFBwc9xMN0nP0bsGVT8QL5WqEDG1nxE3iHYppVjKbLNE6LoAgABUR
|
|
|
|
Oexdf4L8wRSn8H7RjjubXKgfalXnjPPcezAl4qtNoewUdLXEsJQbAgT9/Rde1q6U
|
|
|
|
2XL01trTcDkRHIeT8jZc9F7s43Ec/KToLdZrYJRd/kJMuBUyAyLV+YgGfe0dmSlb
|
|
|
|
e0AIEny52Ci/z+gg+dfKGV9baahqevi8/Sk6zblDsxzZfroUN1eUt/ZCT5LZv7U2
|
|
|
|
NkXHB96TdSnM3IHZfKz2YjVMq2d69NTK4qOrX7Civhq+KFHauROBIdUg5wi8Qraq
|
|
|
|
htF+R9d218s9ZWgzwDX6TW7gA47qDK20vDQTNFMuhnTiaIY5loGAj5cwsuzpSX0s
|
|
|
|
+WmzFgclNHJSeYx2VA4vnLkyEkhnYI4P6QHb43p9qbvWTUGbWPTnv2ZZf6H0Wkzk
|
|
|
|
z3Hwpgdauklck4rdZt00OTp8O/WYPDcb66YbrPW648wPHJQ+i+lBKlGt20GPfXvf
|
|
|
|
Xjy4LiRzQHUauvio29MB3Am4T/y3q5qKD3bKtgaIfjD6KYCCrq7VGs+GrjsN365v
|
|
|
|
LsKjzr/CrlAzDCD7UJ7K1+BvADrqZ+uWBzH9exWBfMWRLdqgFHGAubIDrw55JB4s
|
|
|
|
KDr545r1GVGn0hmRWJuDfHrikQgFr9UlR3NguLR/rBbmzEuZcljzQdu6gL9CGGpR
|
|
|
|
ZgW0WbLulXeN9S5z1KK22Jrq2bdteCvPSQbZrtkbqfWLbBUbWC5TJbmWKF91B+ZY
|
|
|
|
b4qdBhM4d4MF9YA7+TXfOMSIesJJMt65ekEyvyn+lDvJCrbQM+YdUgl41Gglcgx7
|
|
|
|
dQQZpT0fN2TkfAHhjU3VLxbmjIPOukVhcV4D7RyBVjyOYuQAUZCe8HZ61YYYPaQg
|
|
|
|
z+cFOYkBO1tf7OdvRAnZzkADp9bPtRtoDXKuRr+4CjukPr4mCByQb1t5zk3o/24W
|
|
|
|
dvghXFXmALHLumvTaGHSZabLmm7Qoqif2woxOTaIacxxso2zLESblkjnT5gR3aKp
|
|
|
|
UfDo8Bqt2NjnpqqlhlQo8Hw2lqEcdz5OxQ88sbOUDlkYCHV3m5tySopF90EIcn/V
|
|
|
|
YTwkNGBMTuYvqIr/bLtBlkKYuoChCFOGO3bCIoe9PTfSk8ctGAxZDGhoYt0zK4uf
|
|
|
|
iLbMNms15IprTXBixXIR1srht/jxPvA8uwB6YvAxAK1vwKVOjpKCFfokIWmR6WHB
|
|
|
|
0zMB0dhaNgKfVSjArcaqEJdMshg2vtFWCVsn9x/DTkqEgpkRWZ/e67+7udBM3F+6
|
|
|
|
klIrszel8URcu3M7VZ7goP4d4vC6ukQTy/Dzhi/Sx+Fesb17woFJtbWfejObFjHV
|
|
|
|
LGUTuVERdUIUc3V91IG6jyAUBtwdKrZy73LSOJyUsxZUA1mWL3YQn2Cq84ylWxHs
|
|
|
|
Sc0gp51PEjqcjNTO7q5LzrloX4XDbmGnt8uWkZTvmY/wHEI/YKUR6IMCFpbjFlZo
|
|
|
|
bp5Sjaq/lk0VkASjl+s4cw==
|
2019-11-10 18:43:15 -08:00
|
|
|
-----END ENCRYPTED PRIVATE KEY-----
|