Skip to content

Unwrapping an exported wrapped key without device involvement #361

@GalaxyGorilla

Description

@GalaxyGorilla

Hi! The title says it all ... is it possible somehow? The key was generated on the device. Of course the wrap key is known.

I can see that there is even an yubihsm-wrap tool to wrap stuff without a device, but there is no way I'm aware of to unwrap e.g. an exported wrapped key to get the actual sensitive key data.

I tried the decrypt aesccm command but that didn't work and resulted in Failed to decrypt data: Malformed command / invalid data. Note: this is not a capability problem I think since I can en- and decrypt other data.

Since the wrapped key is only dependent on the wrap key (and not the device) there must be a way, right?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions