Skip to content

PKCS12_decrypt_secretbag

NAME

PKCS12_decrypt_secretbag - PKCS12 secret bag decrypt function

SYNOPSIS

#include <openssl/pkcs12.h>

PKCS8_PRIV_KEY_INFO *PKCS12_decrypt_secretbag(const PKCS12_SAFEBAG *bag,
                                              const char *pass, int passlen,
                                              OSSL_LIB_CTX *ctx,
                                              const char *propq);

DESCRIPTION

PKCS12_decrypt_secretbag() decrypts a PKCS#12 secretBag that contains an encrypted PKCS#8 structure (NID_pkcs8ShroudedKeyBag as the bag type within NID_secretBag). This is the format used by Java's keytool to store symmetric secret keys in PKCS#12 files.

bag is the PKCS12_SAFEBAG to decrypt. pass is the passphrase of length passlen. ctx and propq specify the library context and property query string for algorithm lookups.

The returned PKCS8_PRIV_KEY_INFO can be passed to PKCS8_PRIV_KEY_INFO_get1_skey(3) to obtain an EVP_SKEY symmetric key object.

RETURN VALUES

PKCS12_decrypt_secretbag() returns a PKCS8_PRIV_KEY_INFO on success or NULL on error. The caller must free the returned object with PKCS8_PRIV_KEY_INFO_free().

SEE ALSO

PKCS12_SAFEBAG_get1_cert(3), PKCS12_parse(3), PKCS8_decrypt_ex(3)

HISTORY

PKCS12_decrypt_secretbag() was added in OpenSSL 4.2.

Copyright 2026 The OpenSSL Project Authors. All Rights Reserved.

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.