Skip to content

[KeyVault] Fixed PEM Certificate#32879

Open
notyashhh wants to merge 3 commits intodevfrom
yash/kv-version-bump
Open

[KeyVault] Fixed PEM Certificate#32879
notyashhh wants to merge 3 commits intodevfrom
yash/kv-version-bump

Conversation

@notyashhh
Copy link
Member

@notyashhh notyashhh commented Mar 2, 2026

Bumps cryptography from 44.0.1 to 46.0.5.
Bumps pyopenssl from 25.0.0 to 25.3.0

History Notes

This PR is replacing #32830

[Core] Resolve CVE-2026-26007


This checklist is used to make sure that common guidelines for a pull request are followed.

@notyashhh notyashhh requested a review from jiasli as a code owner March 2, 2026 00:03
Copilot AI review requested due to automatic review settings March 2, 2026 00:03
@notyashhh notyashhh requested a review from calvinhzy as a code owner March 2, 2026 00:03
@azure-client-tools-bot-prd
Copy link

azure-client-tools-bot-prd bot commented Mar 2, 2026

️✔️AzureCLI-FullTest
️✔️acr
️✔️latest
️✔️3.12
️✔️3.13
️✔️acs
️✔️latest
️✔️3.12
️✔️3.13
️✔️advisor
️✔️latest
️✔️3.12
️✔️3.13
️✔️ams
️✔️latest
️✔️3.12
️✔️3.13
️✔️apim
️✔️latest
️✔️3.12
️✔️3.13
️✔️appconfig
️✔️latest
️✔️3.12
️✔️3.13
️✔️appservice
️✔️latest
️✔️3.12
️✔️3.13
️✔️aro
️✔️latest
️✔️3.12
️✔️3.13
️✔️backup
️✔️latest
️✔️3.12
️✔️3.13
️✔️batch
️✔️latest
️✔️3.12
️✔️3.13
️✔️batchai
️✔️latest
️✔️3.12
️✔️3.13
️✔️billing
️✔️latest
️✔️3.12
️✔️3.13
️✔️botservice
️✔️latest
️✔️3.12
️✔️3.13
️✔️cdn
️✔️latest
️✔️3.12
️✔️3.13
️✔️cloud
️✔️latest
️✔️3.12
️✔️3.13
️✔️cognitiveservices
️✔️latest
️✔️3.12
️✔️3.13
️✔️compute_recommender
️✔️latest
️✔️3.12
️✔️3.13
️✔️computefleet
️✔️latest
️✔️3.12
️✔️3.13
️✔️config
️✔️latest
️✔️3.12
️✔️3.13
️✔️configure
️✔️latest
️✔️3.12
️✔️3.13
️✔️consumption
️✔️latest
️✔️3.12
️✔️3.13
️✔️container
️✔️latest
️✔️3.12
️✔️3.13
️✔️containerapp
️✔️latest
️✔️3.12
️✔️3.13
️✔️core
️✔️latest
️✔️3.12
️✔️3.13
️✔️cosmosdb
️✔️latest
️✔️3.12
️✔️3.13
️✔️databoxedge
️✔️latest
️✔️3.12
️✔️3.13
️✔️dls
️✔️latest
️✔️3.12
️✔️3.13
️✔️dms
️✔️latest
️✔️3.12
️✔️3.13
️✔️eventgrid
️✔️latest
️✔️3.12
️✔️3.13
️✔️eventhubs
️✔️latest
️✔️3.12
️✔️3.13
️✔️feedback
️✔️latest
️✔️3.12
️✔️3.13
️✔️find
️✔️latest
️✔️3.12
️✔️3.13
️✔️hdinsight
️✔️latest
️✔️3.12
️✔️3.13
️✔️identity
️✔️latest
️✔️3.12
️✔️3.13
️✔️iot
️✔️latest
️✔️3.12
️✔️3.13
️✔️keyvault
️✔️latest
️✔️3.12
️✔️3.13
️✔️lab
️✔️latest
️✔️3.12
️✔️3.13
️✔️managedservices
️✔️latest
️✔️3.12
️✔️3.13
️✔️maps
️✔️latest
️✔️3.12
️✔️3.13
️✔️marketplaceordering
️✔️latest
️✔️3.12
️✔️3.13
️✔️monitor
️✔️latest
️✔️3.12
️✔️3.13
️✔️mysql
️✔️latest
️✔️3.12
️✔️3.13
️✔️netappfiles
️✔️latest
️✔️3.12
️✔️3.13
️✔️network
️✔️latest
️✔️3.12
️✔️3.13
️✔️policyinsights
️✔️latest
️✔️3.12
️✔️3.13
️✔️postgresql
️✔️latest
️✔️3.12
️✔️3.13
️✔️privatedns
️✔️latest
️✔️3.12
️✔️3.13
️✔️profile
️✔️latest
️✔️3.12
️✔️3.13
️✔️rdbms
️✔️latest
️✔️3.12
️✔️3.13
️✔️redis
️✔️latest
️✔️3.12
️✔️3.13
️✔️relay
️✔️latest
️✔️3.12
️✔️3.13
️✔️resource
️✔️latest
️✔️3.12
️✔️3.13
️✔️role
️✔️latest
️✔️3.12
️✔️3.13
️✔️search
️✔️latest
️✔️3.12
️✔️3.13
️✔️security
️✔️latest
️✔️3.12
️✔️3.13
️✔️servicebus
️✔️latest
️✔️3.12
️✔️3.13
️✔️serviceconnector
️✔️latest
️✔️3.12
️✔️3.13
️✔️servicefabric
️✔️latest
️✔️3.12
️✔️3.13
️✔️signalr
️✔️latest
️✔️3.12
️✔️3.13
️✔️sql
️✔️latest
️✔️3.12
️✔️3.13
️✔️sqlvm
️✔️latest
️✔️3.12
️✔️3.13
️✔️storage
️✔️latest
️✔️3.12
️✔️3.13
️✔️synapse
️✔️latest
️✔️3.12
️✔️3.13
️✔️telemetry
️✔️latest
️✔️3.12
️✔️3.13
️✔️util
️✔️latest
️✔️3.12
️✔️3.13
️✔️vm
️✔️latest
️✔️3.12
️✔️3.13

@azure-client-tools-bot-prd
Copy link

azure-client-tools-bot-prd bot commented Mar 2, 2026

️✔️AzureCLI-BreakingChangeTest
️✔️Non Breaking Changes

@yonzhan
Copy link
Collaborator

yonzhan commented Mar 2, 2026

Thank you for your contribution! We will review the pull request and get back to you soon.

@github-actions
Copy link

github-actions bot commented Mar 2, 2026

The git hooks are available for azure-cli and azure-cli-extensions repos. They could help you run required checks before creating the PR.

Please sync the latest code with latest dev branch (for azure-cli) or main branch (for azure-cli-extensions).
After that please run the following commands to enable git hooks:

pip install azdev --upgrade
azdev setup -c <your azure-cli repo path> -r <your azure-cli-extensions repo path>

Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR upgrades two cryptography-related Python packages (cryptography and pyOpenSSL) across all three platform-specific requirements files (Linux, macOS/Darwin, Windows), and regenerates a test PEM certificate fixture to be compatible with the upgraded cryptography library.

Changes:

  • Upgrades cryptography from 44.0.1 to 46.0.5 on all platforms, which drops support for legacy weak ciphers like DES-CBC in PEM encryption.
  • Upgrades pyOpenSSL from 25.0.0 to 25.3.0 on all platforms.
  • Regenerates ec521pw.pem (the EC P-521 encrypted test key) from DES-CBC to AES-256-CBC to restore compatibility with cryptography==46.0.5.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 2 comments.

File Description
requirements.py3.Linux.txt Bumps cryptography to 46.0.5 and pyOpenSSL to 25.3.0
requirements.py3.Darwin.txt Bumps cryptography to 46.0.5 and pyOpenSSL to 25.3.0
requirements.py3.windows.txt Bumps cryptography to 46.0.5 and pyOpenSSL to 25.3.0
ec521pw.pem Regenerated using AES-256-CBC instead of removed DES-CBC to work with the new cryptography version

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

-----BEGIN EC PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: DES-CBC,5A0C299B3F7E3BDD
DEK-Info: AES-256-CBC,B4F94D174FB9F1833836A3AFA1A6635B
Copy link

Copilot AI Mar 2, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR description is empty — the "Description", "Related command", "Testing Guide", and "History Notes" sections all contain only boilerplate template text without any actual content. At minimum, the Description should explain why the PEM certificate was regenerated (i.e., the cryptography library dropped support for DES-CBC in PEM encryption, requiring migration to AES-256-CBC), and the History Notes should reflect the actual version bump changes rather than the template placeholder text.

Copilot uses AI. Check for mistakes.
-----BEGIN EC PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: DES-CBC,5A0C299B3F7E3BDD
DEK-Info: AES-256-CBC,B4F94D174FB9F1833836A3AFA1A6635B
Copy link

Copilot AI Mar 2, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The mydomain.test.encrypted.pem file (used alongside ec521pw.pem in the same test contexts at test lines 1131–1138 and 1321–1329) still uses DES-EDE3-CBC encryption (DEK-Info: DES-EDE3-CBC,...). If the cryptography library version 46.x has also dropped support for Triple-DES (3DES) in legacy PEM encryption (as it has been on a deprecation path), this file would also fail to load, just like the original ec521pw.pem with DES-CBC. This should be verified to ensure that tests importing mydomain.test.encrypted.pem continue to pass with cryptography==46.0.5.

Copilot uses AI. Check for mistakes.
@notyashhh notyashhh changed the title Fixed PEM Certificate [KeyVault] Fixed PEM Certificate Mar 2, 2026
@notyashhh
Copy link
Member Author

/azp run

@azure-pipelines
Copy link

Azure Pipelines successfully started running 3 pipeline(s).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants