<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[wolfSSL - Embedded SSL Library — How to encrypt an RSA 2048 Private key in PKCS#8  format]]></title>
		<link>https://www.wolfssl.com/forums/topic1045-how-to-encrypt-an-rsa-2048-private-key-in-pkcs8-format.html</link>
		<atom:link href="https://www.wolfssl.com/forums/feed-rss-topic1045.xml" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in How to encrypt an RSA 2048 Private key in PKCS#8  format.]]></description>
		<lastBuildDate>Tue, 18 Jul 2017 21:46:54 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: How to encrypt an RSA 2048 Private key in PKCS#8  format]]></title>
			<link>https://www.wolfssl.com/forums/post3388.html#p3388</link>
			<description><![CDATA[<p>Hi delphiwolf,</p><p>Regretfully at this time wolfSSL does not fully support the same output noted by the command: </p><div class="codebox"><pre><code>openssl pkcs8 -topk8 -in server-key.pem -out server-keyPkcs8Enc.pem</code></pre></div><p>This essentially is doing the following steps and I will not what wolfSSL supports:</p><div class="codebox"><pre><code>Step 1: Load in a pem formatted private key - OK supported in wolfSSL
Step 2: Convert PEM key to DER key - OK supported in wolfSSL
Step 3: Create DER formatted PKCS8 object from key - OK supported in wolfSSL
Step 4: Encrypt the PKCS8 object - NOT SUPPORTED
Step 5: Convert DER formatted PKCS8 object to PEM - NOT SUPPORTED</code></pre></div><p>We can get you as for as the unencrypted DER formatted PKCS8 object at this time. The equivalent command in openssl would be:<br /></p><div class="codebox"><pre><code>openssl -pkcs8 -nocrypt -topk8 -inform pem -in server-key.pem -outform der -out server-keyPkcs8.der</code></pre></div><p>Would that be acceptable for your needs? If so please see example code below:</p><div class="codebox"><pre><code>#include &lt;stdio.h&gt;

#include &lt;wolfssl/options.h&gt;
#include &lt;wolfssl/ssl.h&gt;
#include &lt;wolfssl/wolfcrypt/types.h&gt;
#include &lt;wolfssl/wolfcrypt/rsa.h&gt;
#include &lt;wolfssl/wolfcrypt/asn.h&gt;
#include &lt;wolfssl/wolfcrypt/asn_public.h&gt;

byte key[] = &quot;\n\
-----BEGIN RSA PRIVATE KEY-----\n\
MIIEpQIBAAKCAQEAwJUI4VdB8nFtt9JFQScBZcZFrvK8JDC4lc4vTtb2HIi8fJ/7\n\
qGd//lycUXX3isoH5zUvj+G9e8AvfKtkqBf8yl17uuAh5XIuby6G2JVz2qwbU7lf\n\
P9cZDSVP4WNjUYsLZD+tQ7ilHFw0s64AoGPF9n8LWWh4c6aMGKkCba/DGQEuuBDj\n\
xsxAtGmjRjNph27Euxem8+jdrXO8ey8htf1mUQy9VLPhbV8cvCNz0QkDiRTSELlk\n\
wyrQoZZKvOHUGlvHoMDBY3gPRDcwMpaAMiOVoXe6E9KXc+JdJclqDcM5YKS0sGlC\n\
Qgnp2Ai8MyCzWCKnquvE4eZhg8XSlt/Z0E+t1wIDAQABAoIBAQCa0DQPUmIFUAHv\n\
n+1kbsLE2hryhNeSEEiSxOlq64t1bMZ5OPLJckqGZFSVd8vDmp231B2kAMieTuTd\n\
x7pnFsF0vKnWlI8rMBr77d8hBSPZSjm9mGtlmrjcxH3upkMVLj2+HSJgKnMw1T7Y\n\
oqyGQy7E9WReP4l1DxHYUSVOn9iqo85gs+KK2X4b8GTKmlsFC1uqy+XjP24yIgXz\n\
0PrvdFKB4l90073/MYNFdfpjepcu1rYZxpIm5CgGUFAOeC6peA0Ul7QS2DFAq6EB\n\
QcIw+AdfFuRhd9Jg8p+N6PS662PeKpeB70xs5lU0USsoNPRTHMRYCj+7r7X3SoVD\n\
LTzxWFiBAoGBAPIsVHY5I2PJEDK3k62vvhl1loFk5rW4iUJB0W3QHBv4G6xpyzY8\n\
ZH3c9Bm4w2CxV0hfUk9ZOlV/MsAZQ1A/rs5vF/MOn0DKTq0VO8l56cBZOHNwnAp8\n\
yTpIMqfYSXUKhcLC/RVz2pkJKmmanwpxv7AEpox6Wm9IWlQ7xrFTF9/nAoGBAMuT\n\
3ncVXbdcXHzYkKmYLdZpDmOzo9ymzItqpKISjI57SCyySzfcBhh96v52odSh6T8N\n\
zRtfr1+elltbD6F8r7ObkNtXczrtsCNErkFPHwdCEyNMy/r0FKTV9542fFufqDzB\n\
hV900jkt/9CE3/uzIHoumxeu5roLrl9TpFLtG8SRAoGBAOyY2rvV/vlSSn0CVUlv\n\
VW5SL4SjK7OGYrNU0mNS2uOIdqDvixWl0xgUcndex6MEH54ZYrUbG57D8rUy+UzB\n\
qusMJn3UX0pRXKRFBnBEp1bA1CIUdp7YY1CJkNPiv4GVkjFBhzkaQwsYpVMfORpf\n\
H0O8h2rfbtMiAP4imHBOGhkpAoGBAIpBVihRnl/Ungs7mKNU8mxW1KrpaTOFJAza\n\
1AwtxL9PAmk4fNTm3Ezt1xYRwz4A58MmwFEC3rt1nG9WnHrzju/PisUr0toGakTJ\n\
c/5umYf4W77xfOZltU9s8MnF/xbKixsX4lg9ojerAby/QM5TjI7t7+5ZneBj5nxe\n\
9Y5L8TvBAoGATUX5QIzFW/QqGoq08hysa+kMVja3TnKW1eWK0uL/8fEYEz2GCbjY\n\
dqfJHHFSlDBD4PF4dP1hG0wJzOZoKnGtHN9DvFbbpaS+NXCkXs9P/ABVmTo9I89n\n\
WvUi+LUp0EQR6zUuRr79jhiyX6i/GTKh9dwD5nyaHwx8qbAOITc78bA=\n\
-----END RSA PRIVATE KEY-----\n\n&quot;;

int main(int argc, char** argv)
{
    int ret;
    int writeSz = 0;

    byte out[4096];
    byte tmp[4096];
    int tmpSz = (int) sizeof(tmp);
    word32 outSz = sizeof(out);
    word32 keySz = sizeof(key);
    int algoID = RSAk;
    const byte* curveOID = NULL;
    word32 oidSz = 0;
    FILE* file;
    char fName[] = &quot;./wolfSSL-PKCS8-out.pem&quot;;
    char fNameDer[] = &quot;./wolfSSL-PKCS8-out.der&quot;;

    XMEMSET(out, 0, outSz);
    XMEMSET(tmp, 0, tmpSz);

    /* convert pem to der */
    ret = wolfSSL_KeyPemToDer(key, (int) keySz, tmp, tmpSz, NULL);
    if (ret &lt;= 0) {
        printf(&quot;key pem to der failed with error: %d\n&quot;, ret);
        return -1;
    }
    printf(&quot;Key pem to der successful, returned: %d\n&quot;, ret);
    writeSz = ret;

    ret = wc_CreatePKCS8Key(out, &amp;outSz, tmp, (word32) writeSz, algoID, curveOID, oidSz);
    if (ret &lt; 0) {
        printf(&quot;Create PKCS8 Key failed, error returned: %d\n&quot;, ret);
        return -1;
    }

    printf(&quot;SUCCESS, ret = %d\n&quot;, ret);
    writeSz = ret;

/* write DER File */
    file = fopen(fNameDer, &quot;wb&quot;);
    if (!file) {
        printf(&quot;Failed to open file: %s\n&quot;, fNameDer);
        return -1;
    }

    ret = (int) fwrite(out, 1, (size_t) writeSz, file);
    fclose(file);

    if (ret &lt;= 0) {
        printf(&quot;Failed to write file\n&quot;);
        return -1;
    }

/* CURRENTLY NOT SUPPORTED:
 * NOTES:
 * Works but the header is wrong, by default the &quot;PRIVATEKEY_TYPE&quot;
 * actually results in the header:  &quot;-----BEGIN RSA PRIVATE KEY-----&quot;
 * That is incorrect for this particular use-case, it should be: &quot;-----BEGIN PRIVATE KEY-----&quot;
 * we need a new type RSA_PRIVATEKEY_TYPE and for PRIVATEKEY_TYPE to just be
 * private key for this to be supported.
 */
//
//    ret = wc_DerToPem(out, (word32) writeSz, tmp, (word32) tmpSz, PRIVATEKEY_TYPE);
//    if (ret &lt;= 0) {
//        printf(&quot;Der To Pem failed with error: %d\n&quot;, ret);
//        return -1;
//    }
//
//    printf(&quot;Der to Pem returned success: %d\n&quot;, ret);
//    writeSz = ret;
//
/* write PEM File */
//    file = fopen(fName, &quot;wb&quot;);
//    if (!file) {
//        printf(&quot;Failed to open file: %s\n&quot;, fName);
//        return -1;
//    }
//
//    ret = (int) fwrite(tmp, 1, (size_t) writeSz, file);
//    fclose(file);
//
//    if (ret &lt;= 0) {
//        printf(&quot;Failed to write file\n&quot;);
//        return -1;
//    }

    return 0;

}</code></pre></div><p>Warm Regards,</p><p>Kaleb</p>]]></description>
			<author><![CDATA[null@example.com (Kaleb J. Himes)]]></author>
			<pubDate>Tue, 18 Jul 2017 21:46:54 +0000</pubDate>
			<guid>https://www.wolfssl.com/forums/post3388.html#p3388</guid>
		</item>
		<item>
			<title><![CDATA[How to encrypt an RSA 2048 Private key in PKCS#8  format]]></title>
			<link>https://www.wolfssl.com/forums/post3378.html#p3378</link>
			<description><![CDATA[<p>Hi, </p><p>I am trying&nbsp; export a&nbsp; rsa:2048 private key (in pem ) into PKCS#8 format. In openssl, I have used below command to do this.</p><p>openssl pkcs8 -topk8 -in server-key.pem -out server-keyPkcs8Enc.pem</p><p>After searching in the source code ,&nbsp; I could see the below API. </p><p>WOLFSSL_API<br />int wolfSSL_PEM_write_RSAPrivateKey(FILE *fp, WOLFSSL_RSA *rsa,<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; const EVP_CIPHER *enc,<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; unsigned char *kstr, int klen,<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; pem_password_cb *cb, void *u);</p><p>But there is not much information about the parameters. Is there any sample using this API? Can you provide some insight to the <br />parameters used in this API?</p><p>Thanks.</p>]]></description>
			<author><![CDATA[null@example.com (delphiwolf)]]></author>
			<pubDate>Mon, 17 Jul 2017 12:39:06 +0000</pubDate>
			<guid>https://www.wolfssl.com/forums/post3378.html#p3378</guid>
		</item>
	</channel>
</rss>
