Red Hat Bugzilla – Bug 1150645
Importing an RSA private key fails if p < q [rhel-7]
Last modified: 2015-03-05 03:28:38 EST
Description of problem: This problem was reprted upstream. For the original report see https://bugzilla.mozilla.org/show_bug.cgi?id=1049435#c0 Version-Release number of selected component (if applicable): How reproducible: see above link Steps to Reproduce: link anove Actual results: Following message will appear in dialog: The PKCS #12 operation failed for unknown reasons. On the other hand, * "openssl pkcs12" can extract key and certificates. * "openssl verify" can verify signature in EE certificate. Expected results: Key and certificates should be imported. Additional info: From https://bugzilla.mozilla.org/show_bug.cgi?id=1049435#c42 The NSS change that broke this was in NSS 3.16.2. See bug 1021102 and the two bugs named in bug 1021102 comment 0. At that time I thought p > q was required, and any incompatibility would be discovered quickly during testing of mozilla-central nightly builds.
Created attachment 945050 [details] Change RSA_PrivateKeyCheck to not require p > q patch applied upstream https://hg.mozilla.org/projects/nss/rev/358730f7261d
*** Bug 1146592 has been marked as a duplicate of this bug. ***
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2015-0364.html