EldoS | Feel safer!

Software components for data protection, secure storage and transfer

PBEwithMD5andTripleDES interop with Java

Also by EldoS: CallbackRegistry
A component to monitor and control Windows registry access and create virtual registry keys.
#33035
Posted: 04/14/2015 11:15:45
by Darian Miller (Standard support level)
Joined: 06/27/2011
Posts: 48

Using SBB 12 Pro with Delphi - any pointers to working with a Java partner to validate a Password Based encryption cipher when they are using the PBEwithMD5andTripleDES algorithm?
#33036
Posted: 04/14/2015 16:13:01
by Ken Ivanov (EldoS Corp.)

Hi Darian,

While there is a number of ways of implementing password-based encryption (which are generally not compatible with each other), the most widely used one is a PBE algorithm based on RSA PKCS#5 standard, and, according to some materials I've found here and there on the web, JCE gets use of that either.

Yet, SecureBlackbox implementation of PKCS#5 does not support MD5 out of the box due to its age and low popularity. However, as you own the source code, we can instruct you how to amend it to add support for MD5 (there are literally a couple of lines to add). Just let me know if you are ready to go ahead with that and we'll provide you the instructions.

Please note that as we don't know the internals of Java PBE implementation we can't say for sure now whether it will be compatible with SecureBlackbox PKCS#5 implementation, even after introducing the above changes. So we're more like on a PoC stage at the moment.

Cheers,

Ken
#33039
Posted: 04/15/2015 09:32:14
by Darian Miller (Standard support level)
Joined: 06/27/2011
Posts: 48

Thanks... I found this reference

http://stackoverflow.com/questions/9432518/what-is-the-key-size-for-pbewithmd5andtripledes

One guy says the key derivation is custom by Oracle, so likely not standard PKCS#5

In case he's wrong, I've asked the partner to send me sample plain/cipher text along with sample key so I can try to match output. Can you provide those few lines?

Thanks
#33040
Posted: 04/15/2015 09:51:43
by Ken Ivanov (EldoS Corp.)

Hi Darian,

I'm going to create a private helpdesk ticket for you now, where we will continue the discussion. Just wait for an e-mail notification about new ticket from our mail robot, and follow the link in that notification to access your ticket.

Cheers,

Ken
#33075
Posted: 04/20/2015 13:18:27
by Darian Miller (Standard support level)
Joined: 06/27/2011
Posts: 48

Thanks
Also by EldoS: BizCrypto
Components for BizTalk® and SQL Server® Integration Services that let you securely store and transfer information in your business automation solutions.

Reply

Statistics

Topic viewed 1032 times

Number of guests: 1, registered members: 0, in total hidden: 0




|

Back to top

As of July 15, 2016 EldoS Corporation will operate as a division of /n software inc. For more information, please read the announcement.

Got it!