Skip to content

Import PKCS8 EC PEM keys whose public point looks like ASN.1 - #443

Open
Hashim1999164 wants to merge 1 commit into
cisco:masterfrom
Hashim1999164:fix/ecPemPointImport
Open

Hashim1999164 wants to merge 1 commit into
cisco:masterfrom
Hashim1999164:fix/ecPemPointImport

Conversation

@Hashim1999164

@Hashim1999164 Hashim1999164 commented Sep 25, 2026 •

Copy link
Copy Markdown

Fixes #442

Some PKCS8 EC private keys throw RangeError in JWK.asKey when the public point happens to parse as nested ASN.1. An uncompressed point starts with 0x04 then X and Y. When the first byte of X is a plausible length, the forge ASN.1 decoder treats that BIT STRING as an OCTET STRING and the importer then calls readUInt16BE on a one byte buffer.

The importer now keeps that BIT STRING as raw bytes, reads the uncompressed prefix without assuming two bytes are present, and fills X and Y from the private scalar when the point is missing.

I ran the mocha suite. 496 tests passed.

An uncompressed point can decode as an OCTET STRING when the first
coordinate byte is a plausible length. Keep that BIT STRING raw and
do not read past a short buffer.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Error parsing PEM formatted EC key

1 participant