Bug #60632 [Csd]: openssl_seal fails with AES
| From: | bukka@php.net | Date: | Sun, 06 Sep 2015 18:19:51 +0000 |
| Subject: | Bug #60632 [Csd]: openssl_seal fails with AES | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-195812@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=60632&edit=1
ID: 60632
Updated by: bukka@php.net
Reported by: brett at silcon dot com
Summary: openssl_seal fails with AES
Status: Closed
Type: Bug
Package: OpenSSL related
Operating System: Ubuntu 12.04 LTS
PHP Version: 5.4.0-ZS5.6.0
Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
Just a quick update. The closing fix is just fixing the segfualt and it went to 5.6.
I opened a new FR for adding a an IV param because it is out of scope and can be added only to 7
(it's a new param...)
https://bugs.php.net/bug.php?id=70438
That has been fixed in http://git.php.net/?p=php-src.git;a=commit;h=e235cb65fbb2b16eb6ee35c0786d9f42f1a74e2c
and you will be able to use IV cipher algs in PHP 7.
Previous Comments:
------------------------------------------------------------------------
[2015-09-06 15:51:15] bukka@php.net
Automatic comment on behalf of bukka
Revision: http://git.php.net/?p=php-src.git;a=commit;h=d47029167dfc2184f9a630a75a55e145bff8b017
Log: Fix bug #60632: openssl_seal fails with AES
------------------------------------------------------------------------
[2015-09-06 15:40:14] bukka@php.net
Automatic comment on behalf of bukka
Revision: http://git.php.net/?p=php-src.git;a=commit;h=d47029167dfc2184f9a630a75a55e145bff8b017
Log: Fix bug #60632: openssl_seal fails with AES
------------------------------------------------------------------------
[2015-09-01 00:49:45] cmb@php.net
Related To: Bug #70329
------------------------------------------------------------------------
[2015-08-30 18:42:30] bukka@php.net
I think that the patch looks reasonable. I'm just pinging internals if it's ok for 5.6 (it
adds new param...). If so, I will test it, merge it and then port it to 7 as well. If not I will
just disable IV ciphers for 5.6 to prevent segfualt.
There might be is a small concern with locking issue on TS Win as EVP_SealInit uses RAND_bytes but
it's already case for some already used parts (e.g. gen params for new pkey) so don't
think it should be a blocker here.
------------------------------------------------------------------------
[2015-06-22 21:57:09] calebbegly at gmail dot com
This persists in PHP 5.6.10.
There appear to be some commented out code in the source that attempted to set up some stuff for
adding the initialization vector but the call still just passes NULL in for what should be the
pointer to the IV (unsigned char *).
I have to say I was quite surprised to see that this hasn't been resolved yet.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=60632
--
Edit this bug report at https://bugs.php.net/bug.php?id=60632&edit=1