Bug #62102 [Com]: mcrypt CAST128 80/40-bit does not agree with RFC2144 test vectors
| From: | narf at devilix dot net | Date: | Tue, 04 Mar 2014 19:49:31 +0000 |
| Subject: | Bug #62102 [Com]: mcrypt CAST128 80/40-bit does not agree with RFC2144 test vectors | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-184520@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62102&edit=1
ID: 62102
Comment by: narf at devilix dot net
Reported by: nathanpust at hotmail dot com
Summary: mcrypt CAST128 80/40-bit does not agree with RFC2144
test vectors
Status: Open
Type: Bug
Package: mcrypt related
Operating System: Windows XP
PHP Version: 5.3.13
Block user comment: N
Private report: N
New Comment:
I tried commenting earlier, not sure why my comment didn't show up ... this appears to have
been fixed. Both the OP's and my own tests produce the expected results (from RFC2144) on PHP
5.4, 5.5.
Previous Comments:
------------------------------------------------------------------------
[2012-05-22 01:54:16] nathanpust at hotmail dot com
Description:
------------
Please verify that the 80-bit and 40-bit test vectors in RFC2144 Section B.1 do
not agree with the output from mcrypt when using CAST 128 encryption. I provided
a test program with functions that print and parse the hexadecimal.
I am using mcrypt 2.5.8 on php 5.3.13.
The 128-bit test vector does work though. The problem is probably related to the
fact that CAST-128 changes the number of rounds from 16 to 12 when a key is 80
bits or smaller.
I have verified that the test vectors in RFC2144 work with a different piece of
code written in C.
Please let me know if there is a work around.
Test script:
---------------
function str2hex($string)
{
$hex='';
for ($i=0; $i < strlen($string); $i++)
{
$hex .= sprintf("%02x",ord($string[$i])) . ' ';
}
return $hex;
}
function hex2str($x) {
$s='';
foreach(explode("\n",trim(chunk_split($x,2))) as $h) $s.=chr(hexdec($h));
return($s);
}
//RFC-2144
$text = hex2str("0123456789ABCDEF");
//Section B.1 128-bit example
$key = hex2str("0123456712345678234567893456789A");
echo "RFC-2144 Section B.1 128-bit<BR>";
$enc = mcrypt_encrypt(MCRYPT_CAST_128,$key,$text,MCRYPT_MODE_ECB);
echo "ciphertext: " . str2hex($enc);
echo "<BR>";
//RFC-2144
//Section B.1 80-bit example
$key = hex2str("01234567123456782345");
echo "RFC-2144 Section B.1 80-bit<BR>";
$enc = mcrypt_encrypt(MCRYPT_CAST_128,$key,$text,MCRYPT_MODE_ECB);
echo "ciphertext: " . str2hex($enc);
echo "<BR>";
//RFC-2144
//Section B.1 40-bit example
$key = hex2str("0123456712");
echo "RFC-2144 Section B.1 40-bit<BR>";
$enc = mcrypt_encrypt(MCRYPT_CAST_128,$key,$text,MCRYPT_MODE_ECB);
echo "ciphertext: " . str2hex($enc);
echo "<BR>";
Expected result:
----------------
see RFC2144 Section B.1
Actual result:
--------------
see result of provided code.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=62102&edit=1