Using the openssl pkcs12 -export command, is it possible to specify a "-certpbe" value that does not do encryption? Perhaps you only want integrity protection--you don't care whether the certificates are shrouded. The PKCS #12 standard seems to imply that "certBags" can be used as-is; however, all examples of PKCS #12 files that I have seen encrypt the certificates.

Will other common crypto stacks be able to process such a PKCS #12 file (that does not encrypt the certificates)?

Thanks, Sean
_______________________________________________
openssl-users mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-users

Reply via email to