Req #70329 [Opn]: openssl_seal problems

From: Date: Tue, 01 Sep 2015 00:49:46 +0000
Subject: Req #70329 [Opn]: openssl_seal problems
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-195663@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70329&edit=1 ID: 70329 Updated by: cmb@php.net Reported by: totalfix at gmail dot com Summary: openssl_seal problems Status: Open Type: Feature/Change Request Package: OpenSSL related Operating System: any PHP Version: 5.6.12 Block user comment: N Private report: N New Comment: Point #2 has already been reported as bug #60632, and is currently being addressed. Previous Comments: ------------------------------------------------------------------------ [2015-08-22 17:51:39] totalfix at gmail dot com Description: ------------ 1) The function openssl_seal by default uses RC4 cipher, which is considered broken and should not be used. I believe it is not a best practice to leave a weak cipher as a default option as many non-experts (like me) will use it. 2) Even if you want to change ciphers by using the parameter $method, you are limited to ciphers without initialization vectors (so no AES CBC). This is leaves us with ciphers like AES ECB, which is also not recommended. Test script: --------------- openssl_seal($data, $sealed, $ekeys, array($pk1), 'AES-256-CBC'); // this fails, because CBC cannot be used, this is not documented, so the users must use trial and error to figure out which cipher is actually working Expected result: ---------------- Somebody with cyrpto knowledge could read my text and decide if it's worth looking into. I could be wrong, if so, I apologise in advance. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70329&edit=1

« previous php.bugs (#195663) next »