EC keys interoperability issue between openSSL and GnuTLS ?

Nikos Mavrogiannopoulos nmav at gnutls.org
Sat Nov 5 09:28:02 CET 2011


On 11/05/2011 12:46 AM, Fabrice Gautier wrote:
> Hi,
> 
> I generated some EC keys and cert using openssl, and when I try to use
> them with gnutls_serv, it seems that gnutls_serv will just crash.

Ouch. It seems there are two issues here. One bug which didn't report a
parsing error back to the caller (was fixed) and the fact that openssl
uses an old format for storing ECC private keys.

GnuTLS uses the format from RFC 5915 for ECC keys. OpenSSL seems to be
able to read this format, but I couldn't find an option to generate keys
using this format.

regards,
Nikos




More information about the Gnutls-devel mailing list