From 0273af4bde92f056474d97fb95075cb30d67ba1e Mon Sep 17 00:00:00 2001 From: Nicolas Benes Date: Sun, 11 Dec 2022 21:21:55 +0100 Subject: [PATCH] Rewrite test certificates using more modern algorithms The test.p12 file use the RC2-CBC and 3DES-CBC algorithms, which are quite dated and require the `-legacy` option in openssl to read them. ```console $ openssl pkcs12 -in test.p12 -info -noout -legacy -passin pass:test MAC: sha1, Iteration 1 MAC length: 20, salt length: 8 PKCS7 Encrypted data: pbeWithSHA1And40BitRC2-CBC, Iteration 2048 Certificate bag PKCS7 Data Shrouded Keybag: pbeWithSHA1And3-KeyTripleDES-CBC, Iteration 2048 ``` Rewrite the test.p12 file with a current openssl (via p12 -> pem -> p12 conversion) to use more modern algorithms which do not require legacy mode. Rewrite test.pem with a new export of test.p12. ```console $ openssl pkcs12 -in test.p12 -info -noout -passin pass:test MAC: sha256, Iteration 2048 MAC length: 32, salt length: 8 PKCS7 Encrypted data: PBES2, PBKDF2, AES-256-CBC, Iteration 2048, PRF hmacWithSHA256 Certificate bag PKCS7 Data Shrouded Keybag: PBES2, PBKDF2, AES-256-CBC, Iteration 2048, PRF hmacWithSHA256 ``` --- test/test.p12 | Bin 2603 -> 2691 bytes test/test.pem | 60 +++++++++++++++++++++++++------------------------- 2 files changed, 30 insertions(+), 30 deletions(-) diff --git a/test/test.p12 b/test/test.p12 index 764c01fa6bf6111d7a99e297be473a1b2f483602..27b5ee0ac4e24cd3bf010fcfc0dacce7fec15f8f 100644 GIT binary patch literal 2691 zcmai$do&Y_8^^~s=9amHMXpm3*+v_3nM=IQgh+Bvq;i+Yomp~;Ou5UoScnoD%{8S= zb4|JB5j*&vTytKIcIYc%wNvfCvKbNiH7c_`l*e1vt1l ziU_<%Km=a-eJqV2fYSesxQYm%xP7$01lVu4{!KU#7yb-j0R#@A^zX=zkOD#6u#Bec zwwNJKP6z@ruFq{6_~f*PZrq*R3&RB3|boMvHB;m2{=1%F|~ZEY8P3%G9QrALC{_sA6?5kt(;A_2D6O>GC)?bEM{DUUg;iq_{JTtQXzwupCzUestqL z4TE-M^7CAr;F6y*3(lTsD1%%r!*yD7%>=L%T_q`g^&^veUd7&!5;i8wb#m%n=W(R@ z;UXu&qw|TMEW4Z_pX!ZIeDc$$$QRFs2Xn5bg5Yl#-e#;!+~4Rf?SBU%-FnWr(`j9& zV%85$WW({RNERD&)n@ay;}M+)ro=@%{x!}eg=Dkv6Q;MCL@myhwa>vRN<^BP8KTcq zA0}mL(jcyKkoDIQZ~A12ZH5tGx9E3D#OCKn-7HewZKm`2+@u}UxEPCNjE&k}NpGZ< zYSPcwl^kd(<SA}9rfB~SoWW98@VV1yncfc*D{W| z)Fep8DU8kd3N#a6`UwU%ZtDn`L#wnE_o#v$toMb&l5$=mEK2#$<_^|*xA7Hc5(XHB zgr6&4DOQ3%ys!5B3q$JABIrLkfO{&wf7E|BU|ZeN63omSaZCpz+yJ=^T2K5d!W@CwQen~q zlbPNL`ngwki1C8M09he#9};a^LL5tLIYToS8OP=QC=0u1SFo^w3Y4Jg%)rWQDm^H8 z>-wP&c*(hq4@t->igAxYk(_@X?YUM`veCKOGTO{6Td}F_`oeKz!-3ROX?G4xSRx2u z;vc{KBP{Su5CI&pkA3#*8W-RHUB=JL!MPtI_o3>43F_nA6v{8PhW9@O)r5 zyG3627mmj1f(W2Kp^*@KxRHrze8%hc#U<=qJ}!v@?UnB{9mKxj!%DVXU5y1jret%A z08FjYJxO^WsXa}f(_dnrj){-H&(DIbCv08UjQ34mme@`1T%1e*H@6FVI%BhbsdQuSLrECAM~)$b%b&if@s&noZ&i{4ZDtqy!Q=CRk~-r=N?bM=Fv zuq-CUaBEPN-FNpHxE9Pxz5zg)_s48e+wK~J*T6&<4$H^rZJ-Ybm zMBdTf`Vy4RZDvA6UC8S2fMYq&+f7-nBqnFNTp!0tRZiTiQ`$SW+$yGClBNCOfe+SJ z9d{fEi6-%~9aS*+aP$wSX4hp6f%*7~V=Umrp(iq48)0@qUGAFxETz;Tm+H^YPBwKu zytW!g+7gA>t34)^v6~tL9ID*uH*{@S=)PdstgW>GR61*avftOqeX$)|Y@hZ8Mw1Xs$4`OSX%l zb-OJ;$aZT}MZyJuQ@&wa>S(;Odl4{HU3UaRDy5?ipz7Mw3PyPWF7r&9r;mF?@>K5- zY=SZ5Lv(-@#Ena8`&E9mBP<=0YU_Hm($f0D{27N@S@Fo1xrLkIgiy;Fu8T7pPN8-` z(``-7Sm-8=*UlNXPn3GauDG4iJRFsljUY)WT=$DSp%6!#OP_MBE<`u9mM^;vKKQ8X z<#L7C=z$a2sOe9RR_Y_Nw_9k#OXOb3xzq|H;!h=IIv!6Qp3nW z#WaTmRmx_$c^32j5gV|#H`*O{$pigQr-et+vk!POg}&7XAAJWsvyOqO z_ZsMVH%3L8)4#0;cs;|rf9^wib;L^!#e=pa&u}|avQSINntnH8h literal 2603 zcmY+^c{CJy9|rI-#$bj_V(d${v1Wz{SGe|V60(Gu5k|5XvV|J!WEXd29qXl#vKNW$ z+bB1(jV&=uTzj^9-E-de?S21v&hMP(Ip_P|?}H>j5I_b-B!P7U%qkma9CyIZz|24< zu+D)9tkY-p1d;&q`!#{d1d#Jt>>3sJoK1|f?z0jhSi=ysE$ugVr6+UnbW?sETquwtd(&MdZso;W583Fr# zRj1?{`8)d~Dao|KYut6dvy2wwpA4Phbd0a}Iy(nu1!#co$_f{D!0s&Ni$C5le+)G0 zB${pG>D@cI+qpY|z?ZA@B*dY)?%!CChR!>jd;vnSj84xM>xkbGa^0>YgB*6)-OsRn zS2}}(%PMcdRYY-ofp%Wo+AyPHa(fku^;Bdz2xPd}FNyUjiJ(V@d)34(yc-)FgT_=- z9loBfl1;P!5O&wNWacme)DzVv$IWWI=h4ZDRF(NSr21k!coTc|wKoxOsFI^B8Qv@L zVWi`E6+Ch3Rk)|g>&t4*6qi5h;i-Q%?HF^v78Y04%fo-?gKj&*N5FvE!2%ogHr|3J zJT|QF5Y7}AmP5IsxgOE?2@=vm>oRY)sMFame39_X^T7aG=D5V-{zL_Fk*9}~v9e`% zWg5zqLj3S-y*&&rXEzrg_iZH#wsM?Ag9$q)h;8OscYa`G-e;`AS`ngBx?`A$QqP5+ z=^ym`g|GNhY*+hkkTc`eCtqXP)a$-3$6XIlIX9NJHE%cqCqLIscrE^ZmvrF`qo>K&@?f7x2cY}REdfmSJE zzXHNXJxf;TroP$!es}#`u%TtdZ(k5cwf1~t+y1N!xw-?BmZr-#9HuiaZ3Va63~enY zLS!ZPo^S0{ef)X7op^*1*q>{(JH`IR%NDrs?1b<+OAlgvNhjG#J-2GSn0v1~W63gt zDAZ8IxyXCTRrsm=o5BUVo6dcoXg@~aeQ&O0LaX1p$W;jQMo~3_98pwtQ3@5XgFUjLs=RX+<2#(bAFC?V*9A^Iw%=Ck+!vMEU#9eWx-&ae%`jtT%$A z-JTenuOblt@CE6R-vj=*W86N-SxSowYIi=wGS~cfTiq9^teQME4jx!<5vO&f;caOw z&QfB1AjzY7+A!Vi@7A}EBTz1jZ$fSn>E)hkv0Rd~A1El@Q{ivEm3&1>%04@~76u|g zS_>T@*r4>mW8hX@n7|+=f25azc2n@?km2Go7GYH4-EeeWWJM0c1DbbV{7>H<1>Ke=)V1DWt z6FzBCf4X8-TJ{pxZ(Nzbt76+XlC2*$s4;^;5}2I-2Np7c$r40hLZ8(pXE6Xn|HBM~ z0eI%o#u-Fw|ECY*Kl*&?)hwUNol@_d+%a|hbzEzM-euGi{G`X{K5#TuEZ|V}>W_*RwXTJA)b+wy`v`L|sNb{5- z61$Y@(!979jy2)DKD?djAT--!XhrMOLBVqo-z>F6S z3|eMS3!bhIan{QpH`e-T!EdjreD)h}l(*`HG?zUY@~|F(recm5;>rB;=1#c@n(>D^ z7f!gysX}sW+qg!e4d!93iaIX^hk&*?y?F=o20mFFF!oZ^EZZYb7Ucs}El#{{v^jHi zsPc|VC}y%4KRrHhFJors$R9JGGC&r*$->fb9bE!H_OlLRps7^50H08{3f}u(7OAK- zPi1+8lUq({`LM!=#@J$;12NR;BfUn%iqxM>N;{wn+b8Z__PgbK8Tzs9F_{$8%a(`q z1dcCxZMWQ>2D|yop?bcJ4*JFZ49A2zqkN8|E~^{_8VxGZ(~qR*)f8wfL7M}XC$>k1 zN(qS{@(T6D`hbd}FDeFH6k7Bm!`U%8s8TnvgIhAgQZFwy(!PeDR^Ize?QXYc*IQ;O zc4SZLRdmKVHCs<>1&gUq|!cWc^90FVvOin}thBg7^q@_0cuRS0JG% zZ)7+%dYtHrO!Bx+>SXGAU{Km-;?@IIT4KGp>NqJWhM3{X{yjh+C3THrH3?xOG0A7M z`PRPo^Srye<2KZ)e9gOw83Lq+3k7dD%ZgA_hOMyG$Mkw*zMu@d|=c&TgbgVqg4WKKJm|1`9t)As!2AzO|g+8KKQah+*s zmdMva`rpFsrHjkP=&DE#hbP0^Yctzz*gMQKHhQHRga_RR($!m8y{gsdYli^L z?I?VFwB{|M5ITL~A=HQ)D|HWq!*I^ok0RMy)~E(>QDMFGy-Xf;hZ~*EJ6Gpl!X``b zoWFe}C2?QAZCa6775}A4n2*a936ku=u(Gj!Blezv z9Pl^GCdK;B!zbg@k~3Urh8ls53viMU`<8}Mub^LQ+TQ4oU9`D)*Ay$PkuRB46QL;_ z*Xw}JJE{kGNO`1WRN&uwirpCnZ)+Lw>tu5x)V51nLksmPjT?&I_HwgiREyKS^KMkY z4)b%b`&{S6aG2qt;H!%&$Q5z^2^Kbv@^ZbAbMbpq)~%UQ31a>S>B>VAF)C^Nw$0}= zl#(gR^e3@@SsSG}E`6+(7$B^XqU7zz9g0NX$W@JTQ8%n4Ji*zd<*;!~xV6|l+>F&O za6Vua?r}xViP>D`$sy;fyWe=t(ly43?O7te?t%D61&5Kr8J&Q7LGB6qt%dgBHM3Ty zq58vhHDet?+=W|KNbU8qFtikTZgX*hAGk12>CX?vKQ+fc@X@B}$@T@G|Izy?(d0Zz zA1U--9a*_hFyV6mG~f=v_bg#&@kfgPnz>PM5SP6XwEvE{24FZ6koi#ZGM`>Wzc&(z zyoh84Gs&G}1oAThKwRwrQwZl~^X7MH*}7MgJV2iM+Z!Mjcb}5|^MmCyAOpj{0C1zZ ArvLx| diff --git a/test/test.pem b/test/test.pem index bd3a994..fc64d27 100644 --- a/test/test.pem +++ b/test/test.pem @@ -1,8 +1,8 @@ Bag Attributes friendlyName: Minizip localKeyID: 58 47 0B C9 69 23 3A 00 CD 7E 00 94 80 25 34 19 43 A8 C9 6C -subject=/CN=Minizip/O=Minizip/OU=MZ/ST=AZ/C=US/L=Phoenix/emailAddress=nathan@nathanm.com -issuer=/CN=Minizip/O=Minizip/OU=MZ/ST=AZ/C=US/L=Phoenix/emailAddress=nathan@nathanm.com +subject=CN = Minizip, O = Minizip, OU = MZ, ST = AZ, C = US, L = Phoenix, emailAddress = nathan@nathanm.com +issuer=CN = Minizip, O = Minizip, OU = MZ, ST = AZ, C = US, L = Phoenix, emailAddress = nathan@nathanm.com -----BEGIN CERTIFICATE----- MIIDpzCCAo+gAwIBAgIBATANBgkqhkiG9w0BAQsFADCBgDEQMA4GA1UEAwwHTWlu aXppcDEQMA4GA1UECgwHTWluaXppcDELMAkGA1UECwwCTVoxCzAJBgNVBAgMAkFa @@ -30,32 +30,32 @@ Bag Attributes localKeyID: 58 47 0B C9 69 23 3A 00 CD 7E 00 94 80 25 34 19 43 A8 C9 6C Key Attributes: -----BEGIN ENCRYPTED PRIVATE KEY----- -MIIFDjBABgkqhkiG9w0BBQ0wMzAbBgkqhkiG9w0BBQwwDgQIingOHkhKlgECAggA -MBQGCCqGSIb3DQMHBAh61f17heSelQSCBMimyG3FA8h7rYN9jhVWXSmzt8ep9SbB -Q0b7fBL5liTiT5kxpWYbALaKOZ9kwKha2ceeYx7J54n1O+ZguYIVqhprfpl3NpSG -RizuChi30/GRyqejhqdVmZfnGFqyxI9KQce0KXtVq/LPbhNP/YAsSgnt20n+lJ+Z -1rvSFJRsK90bN1Iawl+iqLA9iT//6xf/4BoKFJrnWUUwmqh9Vuak0a1mgalLrx9y -lvakOsKoVgylSKkAzCHZyo5riU5a2ORz7I2gQKYjxcs1hSywhHXsNdDJe3p/j4QC -7kL+20EqwfOUWMBSdPKm25H1Pkent+Zv9O9CzzTKWT/6XVYYCvdRCXy0pOcDcfkL -l2FU8Hi2x7CZ1Q2+36pVo2s/LK/J61vvSvdxDk3Q6Qp6KhwDIPc6knpcgjx6EKnB -5Dn9Jc12KXvkNdc0e6lx1KFX0p1RUYwLGPloywBgAghWsmNOOk6NT5r2fRD2YgUd -4MM823pcnGrK8l+diWO3JqR0P7ElKnxf7C3y8Ql+FNwaht8B7tyNUqgQpCdtmapi -9KOpFQ1iDY52nrwzJTp8muN9S5OPWwIs62kNkd9LpvKAHuWcBm8JR3xB9EmbLNI+ -9gQ1OzNpk7rC8vYwr98fdQ2ERdO3p0kgsgjoUZlCoTx176bmZNPffdJlW9VyUNUp -Cv/763miAHDzeLmb/In6YQHLHBAgFr2A1rAcInQeud8Dh0mDnj01JTjvcn9hM+D7 -mTMqme7OjScEf0t5JvipulMXyPuGmzJtVICiW6GXUBMGswI9oGomZyJYVtY32R8s -c3jsQRxrg8JXKL4vpgkZJ5OBBoNKkr/JOO5ebprzUr5AKSt/1PicD8AZ1g1aS3Jb -0u8gev8APVXiSzMs1WKBZvhsnh1xqsa2WhdBLvw8vuXDz7qgfbVgtSPzVudvPEHU -IC9kN2Qsuxz8B/7r7ZDMNRL0HoSxoG75umWmo7DqtTiojYrzpWvuzGqZERsAx1Ws -BZLP0eIo2u4ZGdJWYSxN0ZQtR/AiEgyE/l78Mbrea84l/4W54Se298Vflz4PANUe -wPRRcOwp99emome098jne15ZRwKKuvAMSKhukTtnrLXipR23TxfvsRBzw9IQ0Yl5 -LhLKWGCacpZSJiWg8ZQ6F3x6Ey19nJKp06vkhP4cdMVHICEkd4sON7s7wdr5BSZ8 -ZUA5pm+9s8AemEYt+V+Njx10lkUNDxVYlJB7ccL2q9jh3BDIUgNUxHEpCKk4Eala -T+qGIuu95fInd/Q0jldXSKwGdIEjejdDzN9+kj5mQwOHix7u/H8EfZTQv0vd41XW -RSpHy2MH6uOSd/LW/+yRtmjfAmiT/0IqLMia6BSqafZWvCZhPtQLSOBam7iCbQ+J -jqEqdqcwFmdLW1wQkmt1uqTTZyOZ9GyLfEqN9eTV2CD09t6fTj4jBB1Wdm+VPxdP -Pde+1jj83sCeMKg3ZHkvufOAkXbBJzH4ocz0S61V3j5AkX0g74EFeWL36F7foRmk -XkDyWJXjnkgTEtl7qC13HN2ueyS3lk8Z7frT2YRz+H8akYyCsr9S5VnnD9U42+52 -s6NzGaIfTSESjprq7E7rrHASSIbvfWV7MIddh40qWRq16YP/rgUTTyesI8QD4kkQ -kYU= +MIIFHDBOBgkqhkiG9w0BBQ0wQTApBgkqhkiG9w0BBQwwHAQIdEObza0X7HkCAggA +MAwGCCqGSIb3DQIJBQAwFAYIKoZIhvcNAwcECFaNr4AhZbmfBIIEyLxrF5LWO64O +iuhuUbPy7I7eXU3efFoWN5rUA++Ul+e8nSAbonTWTh1tedaKJCZAnG0AmJUR0c8A +f/88YsEETLAH9DhakmrRwfwbPugXXI030q9enAKswILwS856hu9RVEmAwwA4pnma +cWFWWdbk7urPFBwc9xMN0nP0bsGVT8QL5WqEDG1nxE3iHYppVjKbLNE6LoAgABUR +Oexdf4L8wRSn8H7RjjubXKgfalXnjPPcezAl4qtNoewUdLXEsJQbAgT9/Rde1q6U +2XL01trTcDkRHIeT8jZc9F7s43Ec/KToLdZrYJRd/kJMuBUyAyLV+YgGfe0dmSlb +e0AIEny52Ci/z+gg+dfKGV9baahqevi8/Sk6zblDsxzZfroUN1eUt/ZCT5LZv7U2 +NkXHB96TdSnM3IHZfKz2YjVMq2d69NTK4qOrX7Civhq+KFHauROBIdUg5wi8Qraq +htF+R9d218s9ZWgzwDX6TW7gA47qDK20vDQTNFMuhnTiaIY5loGAj5cwsuzpSX0s ++WmzFgclNHJSeYx2VA4vnLkyEkhnYI4P6QHb43p9qbvWTUGbWPTnv2ZZf6H0Wkzk +z3Hwpgdauklck4rdZt00OTp8O/WYPDcb66YbrPW648wPHJQ+i+lBKlGt20GPfXvf +Xjy4LiRzQHUauvio29MB3Am4T/y3q5qKD3bKtgaIfjD6KYCCrq7VGs+GrjsN365v +LsKjzr/CrlAzDCD7UJ7K1+BvADrqZ+uWBzH9exWBfMWRLdqgFHGAubIDrw55JB4s +KDr545r1GVGn0hmRWJuDfHrikQgFr9UlR3NguLR/rBbmzEuZcljzQdu6gL9CGGpR +ZgW0WbLulXeN9S5z1KK22Jrq2bdteCvPSQbZrtkbqfWLbBUbWC5TJbmWKF91B+ZY +b4qdBhM4d4MF9YA7+TXfOMSIesJJMt65ekEyvyn+lDvJCrbQM+YdUgl41Gglcgx7 +dQQZpT0fN2TkfAHhjU3VLxbmjIPOukVhcV4D7RyBVjyOYuQAUZCe8HZ61YYYPaQg +z+cFOYkBO1tf7OdvRAnZzkADp9bPtRtoDXKuRr+4CjukPr4mCByQb1t5zk3o/24W +dvghXFXmALHLumvTaGHSZabLmm7Qoqif2woxOTaIacxxso2zLESblkjnT5gR3aKp +UfDo8Bqt2NjnpqqlhlQo8Hw2lqEcdz5OxQ88sbOUDlkYCHV3m5tySopF90EIcn/V +YTwkNGBMTuYvqIr/bLtBlkKYuoChCFOGO3bCIoe9PTfSk8ctGAxZDGhoYt0zK4uf +iLbMNms15IprTXBixXIR1srht/jxPvA8uwB6YvAxAK1vwKVOjpKCFfokIWmR6WHB +0zMB0dhaNgKfVSjArcaqEJdMshg2vtFWCVsn9x/DTkqEgpkRWZ/e67+7udBM3F+6 +klIrszel8URcu3M7VZ7goP4d4vC6ukQTy/Dzhi/Sx+Fesb17woFJtbWfejObFjHV +LGUTuVERdUIUc3V91IG6jyAUBtwdKrZy73LSOJyUsxZUA1mWL3YQn2Cq84ylWxHs +Sc0gp51PEjqcjNTO7q5LzrloX4XDbmGnt8uWkZTvmY/wHEI/YKUR6IMCFpbjFlZo +bp5Sjaq/lk0VkASjl+s4cw== -----END ENCRYPTED PRIVATE KEY-----