Sitelet https://github.com/RustCrypto/formats/pull/2469
Skip to content

pkcs12: PBKDF2-params prf is DEFAULT algid-hmacWithSHA1 - #2469

Open
yuxi-liu-wired wants to merge 1 commit into
RustCrypto:masterfrom
yuxi-liu-wired:fix/pkcs12-pbkdf2-prf-default
Open

yuxi-liu-wired wants to merge 1 commit into
RustCrypto:masterfrom
yuxi-liu-wired:fix/pkcs12-pbkdf2-prf-default

Conversation

@yuxi-liu-wired

Copy link
Copy Markdown
Contributor

RFC 8018 (quoted in the type's doc comment) defines

prf AlgorithmIdentifier {{PBKDF2-PRFs}} DEFAULT algid-hmacWithSHA1

and DER omits a DEFAULT value, so PBKDF2 with HMAC-SHA1 is encoded without prf. openssl pkcs8 -v2prf hmacWithSHA1 produces this, as do older PKCS#12 tools. pkcs12::pbe_params::Pbkdf2Params declares prf as a required field, so these params fail to decode:

// PBKDF2-params from `openssl pkcs8 -topk8 -v2 aes-256-cbc -v2prf hmacWithSHA1`
let der = hex!("3016041027f144970f23ba4f9807dc9db52f00f102020800");
pkcs12::pbe_params::Pbkdf2Params::from_der(&der) // Err: ASN.1 DER message is incomplete
pkcs5::pbes2::Pbkdf2Params::from_der(&der)       // Ok, prf = HmacWithSha1

The fix decodes an absent prf as algid-hmacWithSHA1 ({ id-hmacWithSHA1, NULL }, RFC 8018 B.1.1) and omits it when encoding that value. The derive's default attribute only works for Copy fields (AlgorithmIdentifierOwned isn't), so DecodeValue/EncodeValue are written out, as pkcs5::pbes2::Pbkdf2Params already does. The public struct is unchanged.

Test: tests/pbe_params.rs decodes the OpenSSL params above, checks prf is HMAC-SHA1, and re-encodes byte for byte. It fails on master. The pkcs12.yml matrix passed locally: powerset tests on stable and 1.85, thumbv7em powerset build, fmt, clippy.

This PR was produced by AI agents (Claude) and reviewed by me before submission.

RFC 8018 defines `prf AlgorithmIdentifier {{PBKDF2-PRFs}} DEFAULT
algid-hmacWithSHA1`, and DER omits a DEFAULT value, so PBKDF2 with
HMAC-SHA1 is encoded without prf (e.g. `openssl pkcs8 -v2prf
hmacWithSHA1`, and older PKCS#12 tools). pkcs12::pbe_params::Pbkdf2Params
declared prf as a required field, so such params failed to decode
("ASN.1 DER message is incomplete"). pkcs5::pbes2::Pbkdf2Params already
handles this.

Decode an absent prf as algid-hmacWithSHA1 and omit it when encoding
that value. The derive's `default` only supports Copy fields, so the
DecodeValue/EncodeValue impls are written out, as in pkcs5.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant