On Mon, Feb 24, 2003, Ravun, Oleg wrote: > Hi, > When I try to convert unencrypted private key from PEM format to DER using > openssl pkcs8 -inform PEM -outform DER -in server.pem -out server.der > -nocrypt > > I get the next message: > > Error decrypting key > 1968:error:0906D06C:PEM routines:PEM_read_bio:no start > line:.\crypto\pem\pem_lib.c:663:Expecting: PRIVATE KEY > > server.pem is > -----BEGIN RSA PRIVATE KEY----- > MIICXQIBAAKBgQC6PwmpqLwI52IP3HKVqDK9i0DhmT+3FCYrpuaZgyVfL2rlzd5/ > 2oWzj+bFmUOseqPP5WBrWAJig4wd6OFkK7XQTynUasNoFS4cysTVE9SwvkGhfbbh > 9MGZSyoNT9zcYqC31ZDXsxjstbtPwrZmT9ZQBRHiUuThCNofmiAHPp/wpwIDAQAB > AoGAFN7bhleSOq0zH/PkI0El7necXat+qFVpsZqSXMGFfpUhtX7MYCdstCJ8CciS > /NEBalqZ422JVuDG4tMl7sO3K9+9OwjtxNkEQ7v54olqhzzTH97VyDJXyLqmoi84 > x+wSxc/G80ODy6B6l1gEDIr6N7uizTFzGH0en3LyRJk+4AECQQDhE+k76TGuG8OJ > V7/3NcnBoeao+bMZenXBjLGYim+2fHyacumTY+S00SGmQhG7BqgjPyeDA2AcHCFI > SKGCr2enAkEA09VnV9Fdw+VJEqjP1nLRiV6XEVXB0K59zjz7BiNTZ7mjcDbsFfrH > KEwRk2mTFNq3S2zqEj29tdYYen8DK+xPAQJBAL0k4GFqbEdmKYInbbivSOchyRbD > D9EfagnG1A/edlaicovQeZ1U2wNgo6h16TSEOZO1JN0iXwgAU6/M6X1LLg0CQElF > vspcjC9vhvgiVknaS2pVwrFnVXQmdzO4WigEXhw51TPCe6Uaqnrg3Q99bDfBc7du > RATtQEq+dJciielOgwECQQCTKOw18VMPHoKvLAJgfGKyt74IBP6R0lyKFiu3Z4kL > MAaycKLCTXTl113y8+QDTv/QUAWI/idw9bJz1L4mt7BQ > -----END RSA PRIVATE KEY----- > > I have tried different private keys, for example ca-key.pem from > openssl-0.9.7\apps but I always get the same message. > Does anyone know what I am doing wrong? >
Well I hope that private key isn't a valuable one since its now gone to a public list... That key is isn't in PKCS#8 format. If you want it in PKCS#8 DER format then you need the -topk8 command line argument to the pkcs8 utility. If you want it in PKCS#1 RSAPrivateKey format then use the rsa utility instead. Steve. -- Dr Stephen N. Henson. Core developer of the OpenSSL project: http://www.openssl.org/ Freelance consultant see: http://www.drh-consultancy.demon.co.uk/ Email: [EMAIL PROTECTED], PGP key: via homepage. ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]