[Help-gnutls] Re: gnutls_x509_privkey_export_pkcs8 failure with GNUTLS_PKCS_USE_PBES2_3DES

Simon Josefsson simon at josefsson.org
Thu Sep 6 13:49:25 CEST 2007


Florian Weimer <fweimer at bfk.de> writes:

> The following call (which maps straight to the C API) fails with
> GNUTLS_E_ENCRYPTION_FAILED:
>
>     my $pkcs8 = $key->export_pkcs8(GNUTLS_X509_FMT_PEM, "huhu",
>                                    GNUTLS_PKCS_USE_PBES2_3DES);
>
> With the GNUTLS_PKCS_USE_PKCS12_3DES flag, it works.  Is a special
> format for the password required if the GNUTLS_PKCS_USE_PBES2_3DES
> mode is used?

No, I don't think so.  Maybe the PBES2 approach is buggy.  Could you
debug further why it fails?

/Simon





More information about the Gnutls-help mailing list