Conversation

AOSP uses assorted signing keys in this format for signing releases. I'm aware of the -scrypt switch since I looked into improving this last year. The AOSP signing tooling largely doesn't even support the v2 algorithms and is impractical since it repeatedly decrypts the keys.
1
1
Show replies
If there's a way to use PKCS#5v2.1's PBES2 (i.e. the one that supports PBKDF2) with LibreSSL at all, I haven't figured it out:
Quote Tweet
Replying to @bascule @erincandescent and @davidcadrian
LibreSSL definitely doesn't understand the "-v2prf" argument: $ openssl version LibreSSL 2.8.3 $ openssl pkcs8 -v2prf hmacWithSHA256 -topk8 -in ed25519-priv.der -out ed25519-priv-enc-v2.der unknown option '-v2prf'
1
Show replies