Req #70329 [Opn->Dup]: openssl_seal problems
Edit report at https://bugs.php.net/bug.php?id=70329&edit=1
ID: 70329
Updated by: bukka@php.net
Reported by: totalfix at gmail dot com
Summary: openssl_seal problems
-Status: Open
+Status: Duplicate
Type: Feature/Change Request
Package: OpenSSL related
Operating System: any
PHP Version: 5.6.12
-Assigned To:
+Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
I'm closing this as a duplicate. The reason is that it's requesting two things that
can't be sorted out together. So I have created two new feature requests:
https://bugs.php.net/bug.php?id=70438
which is about adding an IV parameter. This has been done and will be part of PHP 7.
And
https://bugs.php.net/bug.php?id=70439
which is for deprecating of using default method. That cannot be done before 7.1 as there
hasn't been any discussion. As soon as we have a branch for 7 and master will be for 7.1, I
will ping internals about that.
Cheers
Previous Comments:
------------------------------------------------------------------------
[2015-09-01 00:49:45] cmb@php.net
Point #2 has already been reported as bug #60632, and is currently
being addressed.
------------------------------------------------------------------------
[2015-08-22 17:51:39] totalfix at gmail dot com
Description:
------------
1) The function openssl_seal by default uses RC4 cipher, which is considered broken and should not
be used.
I believe it is not a best practice to leave a weak cipher as a default option as many non-experts
(like me) will use it.
2) Even if you want to change ciphers by using the parameter $method, you are limited to ciphers
without initialization vectors (so no AES CBC). This is leaves us with ciphers like AES ECB, which
is also not recommended.
Test script:
---------------
openssl_seal($data, $sealed, $ekeys, array($pk1), 'AES-256-CBC');
// this fails, because CBC cannot be used, this is not documented, so the users must use trial and
error to figure out which cipher is actually working
Expected result:
----------------
Somebody with cyrpto knowledge could read my text and decide if it's worth looking into. I
could be wrong, if so, I apologise in advance.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70329&edit=1
Thread (3 messages)