Error: Bad length of salt (32) for AES when importing a p12 certificate

Werner Koch wk at gnupg.org
Thu Sep 19 11:29:31 CEST 2024


On Thu, 19 Sep 2024 09:07, Nils Schween said:
> A short follow up: I did some more tests and I found that the change of
> the length of the salt array in the function 'parse_shrouded_key_bag'
> suffices to import the certificate. It is actually enough to increase
> the value from 20 to 32. Here is the git diff of my change of minip12.c

Thanks for looking into this.

Do have have a sample P12 file we can put into our regression tests?  In
case you don't want to see that in a public repo we also have an
internal collection of p12 files, in this case mail it to me privately -
of course only if that is test data and not real key material.


Salam-Shalom,

   Werner

-- 
The pioneers of a warless world are the youth that
refuse military service.             - A. Einstein
-------------- next part --------------
A non-text attachment was scrubbed...
Name: openpgp-digital-signature.asc
Type: application/pgp-signature
Size: 247 bytes
Desc: not available
URL: <https://lists.gnupg.org/pipermail/gnupg-users/attachments/20240919/e58d425d/attachment.sig>


More information about the Gnupg-users mailing list