CVE-2024-13454 - Easy-RSA with OpenSSL 3 may create a CA private key using 3DES

Easy-RSA versions after 3.0.5 and before 3.2.0, when used with OpenSSL 3, incorrectly encrypt password-protected CA private keys using the des-ede3-cbc cipher through the easyrsa build-ca command. The expected cipher is aes-256-cbc.

How to Fix the Private CA Key:

  • Use the easyrsa set-pass ca command to re-encrypt the private CA key using the correct cipher algorithm. This is compatible across all Easy-RSA versions.

Additional Recommendation:

  • Upgrade to Easy-RSA version 3.2.0 or newer.

The set-pass command was introduced in Easy-RSA v3.1.2 (GitHub PR #756).

Workflow Using OpenSSL v3 with Easy-RSA:

For each version of Easy-RSA from v3.0.5 through v3.2.1, using build-ca and then set-pass ca to re-encrypt the CA key with a new password:

  • Note: Support for OpenSSL v3 was first introduced in Easy-RSA v3.1.0 (GitHub PR #492).
Version build-ca set-pass
EasyRSA-3.0.5 des-ede3-cbc aes-256-cbc
EasyRSA-3.0.6 des-ede3-cbc aes-256-cbc
EasyRSA-3.0.7 des-ede3-cbc aes-256-cbc
EasyRSA-3.0.8 des-ede3-cbc aes-256-cbc
EasyRSA-3.0.9 des-ede3-cbc aes-256-cbc
EasyRSA-3.1.0 des-ede3-cbc aes-256-cbc
EasyRSA-3.1.1 des-ede3-cbc aes-256-cbc
EasyRSA-3.1.2 des-ede3-cbc aes-256-cbc
EasyRSA-3.1.3 des-ede3-cbc aes-256-cbc
EasyRSA-3.1.4 des-ede3-cbc aes-256-cbc
EasyRSA-3.1.5 des-ede3-cbc aes-256-cbc
EasyRSA-3.1.6 des-ede3-cbc aes-256-cbc
EasyRSA-3.1.7 des-ede3-cbc aes-256-cbc
EasyRSA-3.2.0 aes-256-cbc aes-256-cbc
EasyRSA-3.2.1 aes-256-cbc aes-256-cbc

OpenSSL versions 1.1.0l and 1.1.1w have been tested without issues. OpenSSL 1.x does not exhibit this issue.

However, the set-rsa-pass and set-ec-pass commands have been noted to change the CA key format from PKCS12 to PKC8 for Easy-RSA versions 3.0.9 through 3.1.7, with the cipher consistently being aes-256-cbc.