Req #70329 [Opn]: openssl_seal problems
| From: | cmb@php.net | Date: | Tue, 01 Sep 2015 00:49:46 +0000 |
| Subject: | Req #70329 [Opn]: openssl_seal problems | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-195663@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70329&edit=1
ID: 70329
Updated by: cmb@php.net
Reported by: totalfix at gmail dot com
Summary: openssl_seal problems
Status: Open
Type: Feature/Change Request
Package: OpenSSL related
Operating System: any
PHP Version: 5.6.12
Block user comment: N
Private report: N
New Comment:
Point #2 has already been reported as bug #60632, and is currently
being addressed.
Previous Comments:
------------------------------------------------------------------------
[2015-08-22 17:51:39] totalfix at gmail dot com
Description:
------------
1) The function openssl_seal by default uses RC4 cipher, which is considered broken and should not
be used.
I believe it is not a best practice to leave a weak cipher as a default option as many non-experts
(like me) will use it.
2) Even if you want to change ciphers by using the parameter $method, you are limited to ciphers
without initialization vectors (so no AES CBC). This is leaves us with ciphers like AES ECB, which
is also not recommended.
Test script:
---------------
openssl_seal($data, $sealed, $ekeys, array($pk1), 'AES-256-CBC');
// this fails, because CBC cannot be used, this is not documented, so the users must use trial and
error to figure out which cipher is actually working
Expected result:
----------------
Somebody with cyrpto knowledge could read my text and decide if it's worth looking into. I
could be wrong, if so, I apologise in advance.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70329&edit=1