0

While this question has been asked before and answered at (JWT encrypting payload in python? (JWE)), I can't seem to get JWK working - I have tried importing my plaintext RSA keys and get an error (adding stacktrace below). Can anyone tell me what I'm doing wrong?

Traceback (most recent call last):
  File "statenc.py", line 169, in <module>
    test()
  File "statenc.py", line 155, in test
    keypair = statEnc()
  File "statenc.py", line 48, in __init__
    self.pub_jwk = jwk.JWK.import_from_pem(self, data=self.pubkeystr, password=None)
  File "/usr/lib/python3.6/site-packages/jwcrypto/jwk.py", line 624, in import_from_pem
    data, password=password, backend=default_backend())
  File "/usr/lib/python3.6/site-packages/cryptography/hazmat/primitives/serialization.py", line 20, in load_pem_private_key
    return backend.load_pem_private_key(data, password)
  File "/usr/lib/python3.6/site-packages/cryptography/hazmat/backends/openssl/backend.py", line 978, in load_pem_private_key
    password,
  File "/usr/lib/python3.6/site-packages/cryptography/hazmat/backends/openssl/backend.py", line 1129, in _load_key
    mem_bio = self._bytes_to_bio(data)
  File "/usr/lib/python3.6/site-packages/cryptography/hazmat/backends/openssl/backend.py", line 432, in _bytes_to_bio
    data_char_p = self._ffi.new("char[]", data)
TypeError: initializer for ctype 'char[]' must be a bytes or list or tuple, not str

My code is as follows : (this is for a module which initializes a new RSA key if no existing keys are provided)

def __init__(self, pubkeystr = None, privkeystr = None, sessionkey = None):
        self.pubkeystr = pubkeystr
        self.privkeystr = privkeystr
        self.sessionkey = sessionkey
        if pubkeystr == None or privkeystr == None:  #if blank, generate keys
            self.random_generator = Random.new().read
            self.keys = RSA.generate(1024, self.random_generator)
            self.pubkey = self.keys.publickey()
            self.pubkeystr = self.pubkey.exportKey(format='PEM',
                                            passphrase=None,
                                            pkcs=1).decode('utf-8')
            self.pubcipher = PKCS1_OAEP.new(self.pubkey)
            self.privcipher = PKCS1_OAEP.new(self.keys)
            self.privkeystr = self.keys.exportKey(format='PEM',
                                                passphrase=None,
                                                pkcs=1).decode('utf-8')
            self.privkey = self.keys.exportKey()
        else:  #import the keys
            self.pubkeystr = pubkeystr
            self.privkeystr = privkeystr
            self.pubkey = RSA.importKey(pubkeystr)
            self.pubcipher = PKCS1_OAEP.new(self.pubkey)
            self.privkey = RSA.importKey(privkeystr)
            self.privcipher = PKCS1_OAEP.new(self.privkey)
            if sessionkey == None:
                sessionkey = get_random_bytes(16)
            else:
                self.sessionkey = sessionkey
        # Now setup the JWKs
        self.pub_jwk = jwk.JWK.import_from_pem(self, data=self.pubkeystr, password=None)
        self.priv_jwk = jwk.JWK.import_from_pem(self, data=self.privkeystr, password=None)
        print("%s \n %s" % (self.pub_jwk, self.priv_jwk))
kilokahn
  • 1,136
  • 2
  • 18
  • 38

1 Answers1

1

I know this is an old question, but I stumbled upon it in a frenzy search for answers to other jwcrypto options. I know you've probably solved it, but I'll leave it here for other users. The error is, roughly, that you need to encode the string into bytes.

Changing

self.pub_jwk = jwk.JWK.import_from_pem(self, data=self.pubkeystr, password=None)
self.priv_jwk = jwk.JWK.import_from_pem(self, data=self.privkeystr, password=None)

to

self.pub_jwk = jwk.JWK.import_from_pem(self, data=self.pubkeystr.encode('UTF-8'), password=None)
self.priv_jwk = jwk.JWK.import_from_pem(self, data=self.privkeystr.encode('UTF-8'), password=None)

should fix the problem.

  • Wow. I actually never found a fix, and had to use other methods. Let me try it out and let you know! :) – kilokahn Mar 19 '18 at 14:32
  • jwcrypto version 0.3.2 `AttributeError: type object 'JWK' has no attribute 'import_from_pem'` – isaaclw Apr 03 '19 at 19:51
  • 1
    I know this is very old but you need to create an instance of JWK: `keys = jwk.JWK()` `self.priv_jwk = keys.import_from_pem(data=self.privkeystr.encode('UTF-8'), password=None)` Also remove the first "self" value passed to the call to import_from_pem. – Mayron Sep 24 '19 at 07:24