From: Eric Hodel Date: 2004-07-29T13:53:56+09:00 Subject: Re: OpenSSL and Key Passphrases --Rn7IEEq3VEzCw+ji Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Jamis Buck (jgb3@email.byu.edu) wrote: > Jamis Buck wrote: > >OpenSSL question: > > > >I know you can create new keys easily using Ruby's OpenSSL module: > > > > require 'openssl' > > > > key =3D OpenSSL::PKey::DSA.new( 1024 ) > > > >However, is there a way to generate a new key that is protected by a=20 > >passphrase? I've picked through the ossl source code and don't see an=20 > >obvious answer to this question, so I figure it's either not possible,= =20 > >or the procedure for doing it is non-obvious. > > > >Thanks for any advice! > > > >- Jamis > > >=20 > Duh. It always happens that way. I get desperate, ask the question, and= =20 > then discover the answer: >=20 > require 'openssl' >=20 > key =3D OpenSSL::PKey::DSA.new( 1024 ) > puts key.export( OpenSSL::Cipher::DES.new, "howdy howdy" ) >=20 > *sigh* Sorry for the noise. I've written an SSL certificate generator tool called QuickCert that handles a surprising amount of SSL-foo. (More than even I know it does, probably, since its a compilation of support scripts I found lying about.) I wrote it to help with DRb over SSL, but it is equally suitable for use anywhere an SSL certificate or key is needed. You can download it from: http://segment7.net/projects/ruby/QuickCert/ --=20 Eric Hodel - drbrain@segment7.net - http://segment7.net All messages signed with fingerprint: FEC2 57F1 D465 EB15 5D6E 7C11 332A 551C 796C 9F04 --Rn7IEEq3VEzCw+ji Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.2 (FreeBSD) iD8DBQFBCILhMypVHHlsnwQRAkgPAKCRQXnqNpDQHxefnLoFscet89I3hgCglXYP E2p6Cld4ODta5hH7yCqAUbk= =9Fea -----END PGP SIGNATURE----- --Rn7IEEq3VEzCw+ji--