Bug #60632 [Com]: openssl_seal fails with AES
| From: | calebbegly at gmail dot com | Date: | Mon, 22 Jun 2015 21:57:10 +0000 |
| Subject: | Bug #60632 [Com]: openssl_seal fails with AES | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-193772@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=60632&edit=1
ID: 60632
Comment by: calebbegly at gmail dot com
Reported by: brett at silcon dot com
Summary: openssl_seal fails with AES
Status: Open
Type: Bug
Package: OpenSSL related
Operating System: Ubuntu 12.04 LTS
PHP Version: 5.4.0-ZS5.6.0
Block user comment: N
Private report: N
New Comment:
This persists in PHP 5.6.10.
There appear to be some commented out code in the source that attempted to set up some stuff for
adding the initialization vector but the call still just passes NULL in for what should be the
pointer to the IV (unsigned char *).
I have to say I was quite surprised to see that this hasn't been resolved yet.
Previous Comments:
------------------------------------------------------------------------
[2013-11-18 02:25:22] brett at silcon dot com
I'll have to try it out sometime. The project was deployed 2 years ago with execing command
line tools as a last resort.
Apparently PHP doesn't really care about AES support much. Thanks for looking into it though.
------------------------------------------------------------------------
[2013-11-10 21:15:58] jorrit at wafel dot org
When AES is used, EVP_OpenInit() will try to write the IV to allocated memory. In the current
version that memory address was set to NULL.
I've solved the issue by introducing a new &$iv parameter which will hold the IV if an IV
cipher is used. I've also added an $iv parameter to openssl_open() to be compatible.
Let me know if anything is missing.
Jorrit Kronjee
------------------------------------------------------------------------
[2012-08-14 19:11:36] brett at Silcon dot com
This guy seems to be doing it in C/C++ with openssl so it should be possible
http://shanetully.com/2012/06/openssl-rsa-aes-and-c-oh-my/
int ServerCrypto::rsaEncrypt(const char *msg, size_t msgLen, unsigned char **encMsg) {
size_t encMsgLen = 0;
size_t blockLen = 0;
*encMsg = (unsigned char*)malloc(EVP_PKEY_size(clientPubKey));
if(encMsg == NULL) return FAILURE;
if(!EVP_SealInit(rsaEncryptCtx, EVP_aes_128_cbc(), &rsaSymKey, &rsaSymKeyLen, rsaIV,
&clientPubKey, 1)) {
return FAILURE;
}
if(!EVP_SealUpdate(rsaEncryptCtx, *encMsg + encMsgLen, (int*)&blockLen, (const unsigned
char*)msg, (int)msgLen)) {
return FAILURE;
}
encMsgLen += blockLen;
if(!EVP_SealFinal(rsaEncryptCtx, *encMsg + encMsgLen, (int*)&blockLen)) {
return FAILURE;
}
encMsgLen += blockLen;
EVP_CIPHER_CTX_cleanup(rsaEncryptCtx);
return (int)encMsgLen;
}
------------------------------------------------------------------------
[2012-08-14 19:02:53] brett at silcon dot com
Updated PHP and Ubuntu versions
------------------------------------------------------------------------
[2012-08-14 19:01:22] brett at silcon dot com
The issue remains in the current PHP 5.4 release.
PHP 5.4.0-ZS5.6.0 (cli) (built: Feb 19 2012 10:30:28)
Copyright (c) 1997-2012 The PHP Group
Zend Engine v2.4.0, Copyright (c) 1998-2012 Zend Technologies
with Zend Extension Manager v5.1, Copyright (c) 2003-2010, by Zend Technologies
- with Zend Data Cache v4.0, Copyright (c) 2004-2010, by Zend Technologies [loaded] [licensed]
[disabled]
- with Zend Download Server v1.5.0, Copyright (c) 1998-2010 Zend Technologies Ltd., by Zend
Technologies [loaded] [licensed] [disabled]
- with Zend Job Queue v4.0, Copyright (c) 2004-2010, by Zend Technologies [loaded] [not
licensed] [disabled]
- with Zend Session Clustering v4.0, Copyright (c) 2004-2010, by Zend Technologies [loaded]
[licensed] [disabled]
- with Zend Utils v1.0, Copyright (c) 2004-2010, by Zend Technologies [loaded] [licensed]
[enabled]
- with Zend Optimizer+ v4.1, Copyright (c) 1999-2010, by Zend Technologies [loaded] [licensed]
[disabled]
- with Zend Code Tracing v1.0, Copyright (c) 2009-2010, by Zend Technologies [loaded] [not
licensed] [disabled]
- with Zend Debugger v5.3, Copyright (c) 1999-2010, by Zend Technologies [loaded] [licensed]
[enabled]
- with Zend Page Cache v4.0, Copyright (c) 2004-2010, by Zend Technologies [loaded] [licensed]
[disabled]
[14.08.2012 14:00:27 ERROR] [ ZendExtensionManager.cpp : 657 ( sig_handler ) ] ZendExtensionManager
got SIG 11 at pid 32160 !
[14.08.2012 14:00:27 ERROR] [ ZendExtensionManager.cpp : 670 ( sig_handler ) ] Crash happened during
IDLE stage
[14.08.2012 14:00:27 ERROR] [ ZendExtensionManager.cpp : 673 ( sig_handler ) ] The stack trace
follows:
[14.08.2012 14:00:27 SYSTEM] Obtained 18 stack frames
[14.08.2012 14:00:27 SYSTEM] /usr/local/zend/lib/ZendExtensionManager.so(+0x2b439) [0x7f9bbf15f439]
[14.08.2012 14:00:27 SYSTEM] /usr/local/zend/lib/ZendExtensionManager.so(+0x17ce4) [0x7f9bbf14bce4]
[14.08.2012 14:00:27 SYSTEM] /lib/x86_64-linux-gnu/libc.so.6(+0x364c0) [0x7f9bbfaf64c0]
[14.08.2012 14:00:27 SYSTEM] /lib/x86_64-linux-gnu/libc.so.6(+0x8b560) [0x7f9bbfb4b560]
[14.08.2012 14:00:27 SYSTEM] php(SHA1_Update+0x13e) [0x79620e]
[14.08.2012 14:00:27 SYSTEM] php() [0x7bedf7]
[14.08.2012 14:00:27 SYSTEM] php() [0x7be766]
[14.08.2012 14:00:27 SYSTEM] php(EVP_SealInit+0x14f) [0x76672f]
[14.08.2012 14:00:27 SYSTEM] php() [0x499c33]
[14.08.2012 14:00:27 SYSTEM] php() [0x6af2e5]
[14.08.2012 14:00:27 SYSTEM] php(execute+0x1ce) [0x6b527e]
[14.08.2012 14:00:27 SYSTEM] /usr/local/zend/lib/debugger/php-5.4.x/ZendDebugger.so(+0xed85)
[0x7f9bb1868d85]
[14.08.2012 14:00:27 SYSTEM] php(zend_execute_scripts+0x159) [0x681649]
[14.08.2012 14:00:27 SYSTEM] php(php_execute_script+0x1b8) [0x624718]
[14.08.2012 14:00:27 SYSTEM] php() [0x728370]
[14.08.2012 14:00:27 SYSTEM] php() [0x728921]
[14.08.2012 14:00:27 SYSTEM] /lib/x86_64-linux-gnu/libc.so.6(__libc_start_main+0xed)
[0x7f9bbfae176d]
[14.08.2012 14:00:27 SYSTEM] php() [0x462cea]
Segmentation fault (core dumped)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=60632
--
Edit this bug report at https://bugs.php.net/bug.php?id=60632&edit=1