PKCS#12 password length limit in sm/minip12.c

Bernhard Reiter bernhard at intevation.de
Wed Nov 17 14:45:22 CET 2021


Hello Rainer,

Am Dienstag 09 November 2021 10:21:40 schrieb Rainer Perske:
> > > Before I file a bug report: Is there any good reason for limiting the
> > > password length for PKCS#12 files to 63/2 = 31 bytes in line 354 of
> > > "sm/minip12.c"?

> I'd be glad if you could put it on your to-do list :-)

usually it is helpful if you actually open a task on dev.gnupg.org
and link or quote helpful information.
For example the latest RKCS#12 specs section that deals with it or so.
This helps Werner and other devs to be fast when they have timeslot
to work on the issue in the future.

Patches are also welcome, but would need to have a DCO.

BTW: https://wiki.gnupg.org/X.509
also has a remark and a workaround that seem to be related.
Maybe you can add a link to the new issue there.

Best Regards,
Bernhard


-- 
www.intevation.de/~bernhard   +49 541 33 508 3-3
Intevation GmbH, Osnabrück, DE; Amtsgericht Osnabrück, HRB 18998
Geschäftsführer Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 659 bytes
Desc: This is a digitally signed message part.
URL: <https://lists.gnupg.org/pipermail/gnupg-devel/attachments/20211117/e93e378c/attachment.sig>


More information about the Gnupg-devel mailing list