Skip to content

pkcs12: support supplementary Unicode passwords in UTF-8 KDF - #2477

Open
domenkozar wants to merge 1 commit into
RustCrypto:masterfrom
domenkozar:fix/pkcs12-unicode-passwords
Open

domenkozar wants to merge 1 commit into
RustCrypto:masterfrom
domenkozar:fix/pkcs12-unicode-passwords

Conversation

@domenkozar

Copy link
Copy Markdown

derive_key_utf8 currently constructs an ASN.1 BmpString, so passwords containing supplementary Unicode characters fail before derivation. OpenSSL's PKCS12_key_gen_utf8 accepts these passwords using UTF-16BE surrogate pairs; consequently a PFX password such as päss🔑 can be opened by OpenSSL but fails in Rust consumers of this function.

Encode UTF-8 passwords directly as null-terminated UTF-16BE in a zeroizing buffer. This intentionally extends the UTF-8 helper beyond its previous BMP-only acceptance for OpenSSL interoperability. derive_key_bmp retains its strict ASN.1 BMP input, and derived output for existing BMP passwords, empty passwords, and embedded NULs is unchanged. The existing invalid-rounds behavior remains covered.

Replace the supplementary-character rejection test with independent OpenSSL 3.6.4 vectors covering encryption-key, IV, and MAC derivation, including output spanning multiple digest blocks. Add equivalence coverage for UTF-8 and BMP helpers. The vector-generation command is recorded in the test.

Validation with rustc 1.97.1:

  • cargo fmt --all -- --check
  • cargo clippy -p pkcs12 --all-features --tests -- -D warnings
  • cargo test -p pkcs12 --all-features
  • Tests with defaults disabled for each of: no features, pem, kdf, and pem,kdf, with RUSTFLAGS=-Dwarnings.
  • Independent PKCS#12 import/export probes confirm a supplementary-Unicode password interoperates with OpenSSL in both directions when this patch is applied to a downstream consumer.

Prepared with Codex assistance.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant