Security considerations of "openssl pkcs12 -export -legacy"

"Wall, Stephen" <[email protected]>
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <MW4PR09MB9284048FC0E65BA4F8CA4EE5EE9FA@MW4PR09MB9284.namprd09.prod.outlook.com>
What are the ramifications of using the “-legacy” options to “pkcs12 -export” from a security perspective?  I’ve been told by another engineer that older versions of Android (10, 11) are not able to parse the format that OpenSSL 3 defaults to, and am considering implementing an option to allow users to export PKCS12 files using the older format, but I’m concerned with how bad of a security risk that is.  It doesn’t seem like Sweet32 is really applicable, as that requires large amounts of data to exercise. Is there a real vulnerability here that could compromise users private keys?

Thanks.
- Steve

-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/MW4PR09MB9284048FC0E65BA4F8CA4EE5EE9FA%40MW4PR09MB9284.namprd09.prod.outlook.com.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.