## CVE-2024-13454 - Easy-RSA with OpenSSL 3 may create a CA private key using 3DES
-
Easy-RSA versions after 3.0.5 and before 3.2.0, when used with OpenSSL 3, incorrectly encrypt password-protected CA private keys using the `des-ede3-cbc` cipher through the `easyrsa build-ca` command. The expected cipher is `aes-256-cbc`.
+
Using Easy-RSA after version 3.0.5 and before 3.2.0 on systems using
+
OpenSSL 3 will incorrectly encrypt password protected CA private keys
+
using cipher:des-ede3-cbc when using the `easyrsa build-ca` command.
+
The algorithm expected to be used is cipher:aes-256-cbc.
-
### How to Fix the Private CA Key:
-
- Use the `easyrsa set-pass ca` command to re-encrypt the private CA key using the correct cipher algorithm. This is compatible across all Easy-RSA versions.
+
How to fix the private CA key:
+
- Use the `easyrsa set-pass ca` command. This will re-encrypt the
+
private CA key using the proper cipher algorithm. This will work
+
on all Easy-RSA versions.
-
### Additional Recommendation:
+
Additional recommendation:
- Upgrade to Easy-RSA version 3.2.0 or newer.
-
The `set-pass` command was introduced in Easy-RSA v3.1.2 ([GitHub PR #756](https://github.com/OpenVPN/easy-rsa/pull/756)).
-
-
### Workflow Using OpenSSL v3 with Easy-RSA:
-
For each version of Easy-RSA from v3.0.5 through v3.2.1, using `build-ca` and then `set-pass ca` to re-encrypt the CA key with a new password:
-
-
- **Note**: Support for OpenSSL v3 was first introduced in Easy-RSA v3.1.0 ([GitHub PR #492](https://github.com/OpenVPN/easy-rsa/pull/492)).
OpenSSL versions `1.1.0l` and `1.1.1w` have been tested without issues. OpenSSL 1.x does not exhibit this issue.
-
-
However, the `set-rsa-pass` and `set-ec-pass` commands have been noted to change the CA key format from PKCS12 to PKC8 for Easy-RSA versions 3.0.9 through 3.1.7, with the cipher consistently being `aes-256-cbc`.
\
No newline at end of file
+
Command `set-pass` was introduced in Easy-RSA-3.1.2 (https://github.com/OpenVPN/easy-rsa/pull/756).
+
+
Using **OpenSSL v3** with each version of Easy-RSA command `build-ca`, then using Easy-RSA command `set-pass ca` to re-encrypt the CA key with a new password:
+
+
**Note**: Easy-RSA support for OpenSSL v3 was first introduced in Easy-RSA `v3.1.0` (https://github.com/OpenVPN/easy-rsa/pull/492).
OpenSSL version `1.1.0l` and `1.1.1w` has been tested and no issues were found. OpenSSL 1.x is not expected to have this issue.
+
+
However the `set-rsa-pass` and `set-ec-pass` were found to change the CA key format from PKCS12 to PKC8 for Easy-RSA versions `3.0.9` through `3.1.7`. In all cases, the cipher used was `aes-256-cbc`.