Skip to content
Commit Detail

Commit 05e4190

Author
Yagiz Nizipli <yagiz@cloudflare.com> 2026-03-11 00:00:00 +0000
Parents
b9b4ddf
Tree
79f9ef7
Fix cipher/passphrase bypass in Node crypto key export

AsymmetricKey::exportKeyExt() accepted cipher and passphrase parameters
but never forwarded them to the PrivateKeyEncodingConfig passed to
writePrivateKey(). The config was constructed with only (false,
formatType, encType), leaving its cipher and passphrase fields at their
defaults (nullptr / nullopt). This caused writePrivateKey() to always
produce an unencrypted PEM regardless of what the caller requested.

Populate config.cipher via ncrypto::getCipherByName() and
config.passphrase via DataPointer::Alloc() before passing the config to
writePrivateKey(), matching the pattern already used by
tryParsingPrivate() in the same file. Add regression tests for RSA and
EC encrypted private key export round-trips.

Files changed