Using PCKS#12 certifcate with non-ASCII password

Viewed 4462

I trying to open PKCS#12 file, but because password is not ASCII (contains polish characters) I getting "Password is not ASCII" exception when executing KeyStore.load(). Is there any solution to using this certificate?

2 Answers

The RFC 7292 specifies the support of ASCII and UTF-8 encodings for passwords as a recommendation only.

Java API supports only ASCII passwords.

So, the workaround is to change the keystore password.

Example

Generate private key and certificate

openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 365 -nodes -subj "/CN=test/C=CH/ST=Zurich/L=Zurich/O=Test Org/OU=Test Unit"

Create a PKCS 12 keystore with a non-ASCII password (пароль)

openssl pkcs12 -export -in cert.pem -inkey key.pem -out keystore.p12 -password pass:пароль

Get the PKCS 12 keystore info using OpenSSL

openssl pkcs12 -info -in keystore.p12 -noout -password pass:пароль

Trying to get the keystore info using Java keytool results in exception Password is not ASCII

keytool -list -v -keystore keystore.p12 -storepass пароль -storetype PKCS12

java.io.IOException: keystore password was incorrect
    at java.base/sun.security.pkcs12.PKCS12KeyStore.engineLoad(PKCS12KeyStore.java:2108)
    at java.base/sun.security.util.KeyStoreDelegator.engineLoad(KeyStoreDelegator.java:222)
    at java.base/java.security.KeyStore.load(KeyStore.java:1479)
    at java.base/sun.security.tools.keytool.Main.doCommands(Main.java:946)
    at java.base/sun.security.tools.keytool.Main.run(Main.java:397)
    at java.base/sun.security.tools.keytool.Main.main(Main.java:390)
Caused by: java.security.UnrecoverableKeyException: failed to decrypt safe contents entry: java.io.IOException: getSecretKey failed: Password is not ASCII

So, the keystore password has to be changed. There is no easy way to change a PKCS 12 keystore password using OpenSSL. The existing keystore has to be converted to PEM and a new keystore with a new password has to be created instead

openssl pkcs12 -in keystore.p12 -out keystore.txt -nodes -password pass:пароль
openssl pkcs12 -export -in keystore.txt -out newkeystore.p12 -password pass:password
rm keystore.txt

Don't forget to do the last step to remove unencrypted PEM key.

Now, it's possible to get the keytool info using both OpenSSL and Java keytool

openssl pkcs12 -info -in newkeystore.p12 -noout -password pass:password
keytool -list -v -keystore newkeystore.p12 -storepass password -storetype PKCS12

Your keystore contains 1 entry

Usually, it's better to use Java keytool to change a keystore password as described in the answer https://stackoverflow.com/a/50900084/7873775

keytool -storetype pkcs12 -keystore newkeystore.p12 -storepasswd -storepass password -new newpassword

But it doesn't work for keystores with non-ASCII passwords.

i have change my password "889002333" to "amrajat" and my error solve

Related