I trying to open PKCS#12 file, but because password is not ASCII (contains polish characters) I getting "Password is not ASCII" exception when executing KeyStore.load(). Is there any solution to using this certificate?
I trying to open PKCS#12 file, but because password is not ASCII (contains polish characters) I getting "Password is not ASCII" exception when executing KeyStore.load(). Is there any solution to using this certificate?
The RFC 7292 specifies the support of ASCII and UTF-8 encodings for passwords as a recommendation only.
Java API supports only ASCII passwords.
So, the workaround is to change the keystore password.
Generate private key and certificate
openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 365 -nodes -subj "/CN=test/C=CH/ST=Zurich/L=Zurich/O=Test Org/OU=Test Unit"
Create a PKCS 12 keystore with a non-ASCII password (пароль)
openssl pkcs12 -export -in cert.pem -inkey key.pem -out keystore.p12 -password pass:пароль
Get the PKCS 12 keystore info using OpenSSL
openssl pkcs12 -info -in keystore.p12 -noout -password pass:пароль
Trying to get the keystore info using Java keytool results in exception Password is not ASCII
keytool -list -v -keystore keystore.p12 -storepass пароль -storetype PKCS12
java.io.IOException: keystore password was incorrect
at java.base/sun.security.pkcs12.PKCS12KeyStore.engineLoad(PKCS12KeyStore.java:2108)
at java.base/sun.security.util.KeyStoreDelegator.engineLoad(KeyStoreDelegator.java:222)
at java.base/java.security.KeyStore.load(KeyStore.java:1479)
at java.base/sun.security.tools.keytool.Main.doCommands(Main.java:946)
at java.base/sun.security.tools.keytool.Main.run(Main.java:397)
at java.base/sun.security.tools.keytool.Main.main(Main.java:390)
Caused by: java.security.UnrecoverableKeyException: failed to decrypt safe contents entry: java.io.IOException: getSecretKey failed: Password is not ASCII
So, the keystore password has to be changed. There is no easy way to change a PKCS 12 keystore password using OpenSSL. The existing keystore has to be converted to PEM and a new keystore with a new password has to be created instead
openssl pkcs12 -in keystore.p12 -out keystore.txt -nodes -password pass:пароль
openssl pkcs12 -export -in keystore.txt -out newkeystore.p12 -password pass:password
rm keystore.txt
Don't forget to do the last step to remove unencrypted PEM key.
Now, it's possible to get the keytool info using both OpenSSL and Java keytool
openssl pkcs12 -info -in newkeystore.p12 -noout -password pass:password
keytool -list -v -keystore newkeystore.p12 -storepass password -storetype PKCS12
Your keystore contains 1 entry
Usually, it's better to use Java keytool to change a keystore password as described in the answer https://stackoverflow.com/a/50900084/7873775
keytool -storetype pkcs12 -keystore newkeystore.p12 -storepasswd -storepass password -new newpassword
But it doesn't work for keystores with non-ASCII passwords.