> If so, would it be possible in principle to decrypt an encrypted PKCS#7 envelope only knowing which AES key was used ? Yes. But maybe not with the openssl api's :)