Menu

PBE Iteration Count on PKCS12 Keystores created by EJBCA

2021-04-08
2021-04-12
  • Götz  Golla

    Götz Golla - 2021-04-08

    We are using the EJBCA community edition, currently 6.15.2.6. We recently found that the iteration count parameter on the MAC and key algorithms of the pkcs12 keystores created by the EJBCA seem to have changed from 1024 to 102400. This can be seen by, e.g., using "openssl asn1parse" on the p12 keystores.

    The value of 102400 seems to be unreasonably high (the default in openssl is 2048) and in fact leads to performance problems in one of our client applications using a client certificate in pkcs12 format.

    Can it be verified that the iteration count is set by the EJBCA, and that the value was changed with the community edition 6.15.2.6 ?

    How can we change this parameter in the EJBCA ?

    Thanks !
    Götz

     
  • Götz  Golla

    Götz Golla - 2021-04-12

    Since this problem begins to become production critical for us and we need help, I have rewritten the post with some more details in the help section of the forums. This post can thus be ignored.

     

Log in to post a comment.