Security considerations of "openssl pkcs12 -export -legacy"
"Wall, Stephen" <[email protected]>
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <MW4PR09MB9284048FC0E65BA4F8CA4EE5EE9FA@MW4PR09MB9284.namprd09.prod.outlook.com> |
What are the ramifications of using the “-legacy” options to “pkcs12 -export” from a security perspective? I’ve been told by another engineer that older versions of Android (10, 11) are not able to parse the format that OpenSSL 3 defaults to, and am considering implementing an option to allow users to export PKCS12 files using the older format, but I’m concerned with how bad of a security risk that is. It doesn’t seem like Sweet32 is really applicable, as that requires large amounts of data to exercise. Is there a real vulnerability here that could compromise users private keys? Thanks. - Steve -- You received this message because you are subscribed to the Google Groups "openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/MW4PR09MB9284048FC0E65BA4F8CA4EE5EE9FA%40MW4PR09MB9284.namprd09.prod.outlook.com.