[SLE] cannot remove passphrase form apache ssl key

From: John Chronakis (linux_at_vmpsoft.com)
Date: 05/28/04

  • Next message: Bo Jacobsen: "[SLE] Where does YAST "hide" info on which software packages is installed"
    Date: Fri, 28 May 2004 13:53:58 +0300
    To: suse-linux-e@suse.com
    
    

    Hello,

    I have created a self signed certificate for apache2 encrypted with a
    key and a passphrase.

    Everything works well and now I want to remove the passphrase from the key.
    However, openssl does not allow me to enter an empty passphrase

    # openssl rsa -des3 -in apache.key -out apache.key.plain
    Enter pass phrase for secure.htr.gr.apache.key: *******
    writing RSA key
    Enter PEM pass phrase:
    Verifying - Enter PEM pass phrase:
    phrase is too short, needs to be at least 4 chars

    I get a similar mistake error if I try to create a key with an empty
    passphrase
    (23369:error:28069065:lib(40):UI_set_result:result too
    small:ui_lib.c:847:You must type in 4 to 8191 characters)

    Any suggestios?

    Thanks

    -- 
    Check the headers for your unsubscription address
    For additional commands send e-mail to suse-linux-e-help@suse.com
    Also check the archives at http://lists.suse.com
    Please read the FAQs: suse-linux-e-faq@suse.com
    

  • Next message: Bo Jacobsen: "[SLE] Where does YAST "hide" info on which software packages is installed"

    Relevant Pages

    • Re: Should be in crypto for criminals Re: just stupid?
      ... > brute force the pass phrase at all, you can brute force it to obtain ... passphrases by making it so that only one passphrase needs to be remembered ... passphrases are pathetically low in entropy. ... > That's not the pass phrase generator. ...
      (sci.crypt)
    • Re: Should be in crypto for Asswood Re: just stupid?
      ... >> As I have explained before, because of human inability to memorize ... >> fixed by implementing forward secrecy. ... > You are making assumptions again about pass phrase style. ... >> a workable passphrase for the system. ...
      (sci.crypt)
    • Re: Should be in crypto for criminals Re: just stupid?
      ... >>brute force the pass phrase at all, you can brute force it to obtain ... > passphrases by making it so that only one passphrase needs to be remembered ... >>the design considerations for CryptoSMS is that it leave ... > passphrases are pathetically low in entropy. ...
      (sci.crypt)
    • Re: Newbie - Are You Sure Thats the Correct Pass Phrase?
      ... The pass phrase is run through PKCS # 5 algo 2. ... produces the crypto key for certain columns in database accesses. ... Sorry, my mistake, I thought passphrase was used when the user signs in. ... and a hash to generate the encryption key. ...
      (sci.crypt)
    • Re: md5 collisions and speeding tickets
      ... I would dispute that the i 20 character passphrase has only 20 bits of entropy. ... ("English phrase " is a very amorphous concept). ...
      (sci.crypt)