Skip to content

Update to for DProperties PKCS#11/MSCAPI providers - #830

Open
jonwltn wants to merge 2 commits into
kaikramer:mainfrom
jonwltn:dproperties-update
Open

jonwltn wants to merge 2 commits into
kaikramer:mainfrom
jonwltn:dproperties-update

Conversation

@jonwltn

@jonwltn jonwltn commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

This PR updates DProperties so that it does not show PKCS#11 or MSCAPI private keys as locked. It includes the following improvements:

  • Don't indicate that PKCS#11 and MSCAPI private keys are locked.
  • Display the curve for EC keys.
  • Automatically unlock key entries for PKCS#12 and PEM key stores, if possible.

Added the EC curve:
image

This is what MSCAPI private EC key looks like:
image

RSA key:
image

I should probably be consistent with the key sizes. Previously, DProperites just showed "Locked - unload to get properites", which isn't totally true, but it hid all the unknown details. Perhaps for the PKCS#11 private keys, it would be better to state that the key details are protected.

Finally, I noticed that for RSA and DSA keys DProperties displays the key parameters/fields, but it does not do that for all the new key pair types that have been added. Do you want to include all the private/public key fields in DProperties, too?

- Don't indicate that PKCS#11 and MSCAPI private keys are locked.
- Display the curve for EC keys.
- Automatically unlock key entries, if possible.
@kaikramer

Copy link
Copy Markdown
Owner

I should probably be consistent with the key sizes. Previously, DProperites just showed "Locked - unload to get properites", which isn't totally true, but it hid all the unknown details. Perhaps for the PKCS#11 private keys, it would be better to state that the key details are protected.

Sounds reasonable.

Finally, I noticed that for RSA and DSA keys DProperties displays the key parameters/fields, but it does not do that for all the new key pair types that have been added. Do you want to include all the private/public key fields in DProperties, too?

I could imagine scenarios where this might be useful in combination with the text export (the "Copy" button) to get a list of the keys in the keystore with details - if there are more than a couple of keys in it. But I think this is a rather exotic use case and it should be very low on the priority list.

@jonwltn

jonwltn commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

I'm still working on this.

@jonwltn

jonwltn commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

This resolves the EC and RSA inconsistencies for protected private keys.

image

This one is ready for final review and comments.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants