MacOS RSA DER / OpenSSL 3.4.0 RSA256 EncodingKey::from_rsa_der broken
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 45/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Ferma
- Stack tecnologico
- rust
- Ambito
- cryptography
Direzione di ricerca
Start with the linked minimal repro and EncodingKey::from_rsa_der using the generated private.der and public.der under OpenSSL 3.4. Compare this with the working from_rsa_pem path and verify parsing on macOS. Done means standard 2048- and 3072-bit RSA DER keys load successfully while PEM loading remains working.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Seen also #55
Description:
Using OpenSSL 3.4.0 on MacOS, EncodingKey::from_rsa_der fails to parse standard RSA DER keys.
Steps to Reproduce:
Minimal repro here: der_broken
jsonwebtoken = "9.3.1"
Shell script to generate the key:
#!/bin/zsh
if [ -z "$1" ]; then
num_bits=3072
else
num_bits=$1
fi
# Generate 3072-bit RSA private key directly in PEM
openssl genrsa -out private.pem $num_bits
openssl rsa -outform DER -in private.pem -out private.der
openssl rsa -RSAPublicKey_out -outform DER -in private.pem -out public.der
# Base64 encode the DER files (without newlines)
base64 < private.der | tr -d '\n' > private.der.b64
base64 < public.der | tr -d '\n' > public.der.b64
# Write to .env cleanly without extra newlines
{
printf "JWT_PRIVATE=%s\n" "$(cat private.der.b64)"
printf "JWT_PUBLIC=%s\n" "$(cat public.der.b64)"
} > .env
Notes:
- The DER produced is valid (can be parsed by OpenSSL and other libraries).
- Likely regression related to stricter ASN.1 parsing.
- Happens on both 2048 and 3072-bit keys.
- PEM-based loading (from_rsa_pem) still works fine.
- Lingua principale
- Rust
- Stelle
- 2.1k
- Fork
- 367
- Merge medio
- 5g 12h
- PR unite (30g)
- 2
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di Keats/jsonwebtoken
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
Keats/jsonwebtoken#544 · 1 commento ·
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
Keats/jsonwebtoken#542 · 1 commento ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
Keats/jsonwebtoken#519 · 2 commenti ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
Keats/jsonwebtoken#497 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
Keats/jsonwebtoken#297 · 19 commenti · 2 reazioni ·
Tutte le issue di Keats/jsonwebtoken
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
aws-samples/sample-pacer#76 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
axodotdev/cargo-dist#2523 ·
I maintainer di solito rispondono entro 2 giorni