Bug #62102 [Com]: mcrypt CAST128 80/40-bit does not agree with RFC2144 test vectors

From: Date: Tue, 04 Mar 2014 19:49:31 +0000
Subject: Bug #62102 [Com]: mcrypt CAST128 80/40-bit does not agree with RFC2144 test vectors
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184520@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62102&edit=1 ID: 62102 Comment by: narf at devilix dot net Reported by: nathanpust at hotmail dot com Summary: mcrypt CAST128 80/40-bit does not agree with RFC2144 test vectors Status: Open Type: Bug Package: mcrypt related Operating System: Windows XP PHP Version: 5.3.13 Block user comment: N Private report: N New Comment: I tried commenting earlier, not sure why my comment didn't show up ... this appears to have been fixed. Both the OP's and my own tests produce the expected results (from RFC2144) on PHP 5.4, 5.5. Previous Comments: ------------------------------------------------------------------------ [2012-05-22 01:54:16] nathanpust at hotmail dot com Description: ------------ Please verify that the 80-bit and 40-bit test vectors in RFC2144 Section B.1 do not agree with the output from mcrypt when using CAST 128 encryption. I provided a test program with functions that print and parse the hexadecimal. I am using mcrypt 2.5.8 on php 5.3.13. The 128-bit test vector does work though. The problem is probably related to the fact that CAST-128 changes the number of rounds from 16 to 12 when a key is 80 bits or smaller. I have verified that the test vectors in RFC2144 work with a different piece of code written in C. Please let me know if there is a work around. Test script: --------------- function str2hex($string) { $hex=''; for ($i=0; $i < strlen($string); $i++) { $hex .= sprintf("%02x",ord($string[$i])) . ' '; } return $hex; } function hex2str($x) { $s=''; foreach(explode("\n",trim(chunk_split($x,2))) as $h) $s.=chr(hexdec($h)); return($s); } //RFC-2144 $text = hex2str("0123456789ABCDEF"); //Section B.1 128-bit example $key = hex2str("0123456712345678234567893456789A"); echo "RFC-2144 Section B.1 128-bit<BR>"; $enc = mcrypt_encrypt(MCRYPT_CAST_128,$key,$text,MCRYPT_MODE_ECB); echo "ciphertext: " . str2hex($enc); echo "<BR>"; //RFC-2144 //Section B.1 80-bit example $key = hex2str("01234567123456782345"); echo "RFC-2144 Section B.1 80-bit<BR>"; $enc = mcrypt_encrypt(MCRYPT_CAST_128,$key,$text,MCRYPT_MODE_ECB); echo "ciphertext: " . str2hex($enc); echo "<BR>"; //RFC-2144 //Section B.1 40-bit example $key = hex2str("0123456712"); echo "RFC-2144 Section B.1 40-bit<BR>"; $enc = mcrypt_encrypt(MCRYPT_CAST_128,$key,$text,MCRYPT_MODE_ECB); echo "ciphertext: " . str2hex($enc); echo "<BR>"; Expected result: ---------------- see RFC2144 Section B.1 Actual result: -------------- see result of provided code. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=62102&edit=1

« previous php.bugs (#184520) next »