Req #70329 [Opn->Dup]: openssl_seal problems

From: Date: Sun, 06 Sep 2015 18:25:57 +0000
Subject: Req #70329 [Opn->Dup]: openssl_seal problems
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-195813@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70329&edit=1

 ID:                 70329
 Updated by:         bukka@php.net
 Reported by:        totalfix at gmail dot com
 Summary:            openssl_seal problems
-Status:             Open
+Status:             Duplicate
 Type:               Feature/Change Request
 Package:            OpenSSL related
 Operating System:   any
 PHP Version:        5.6.12
-Assigned To:        
+Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

I'm closing this as a duplicate. The reason is that it's requesting two things that
can't be sorted out together. So I have created two new feature requests:

https://bugs.php.net/bug.php?id=70438

which is about adding an IV parameter. This has been done and will be part of PHP 7.

And

https://bugs.php.net/bug.php?id=70439

which is for deprecating of using default method. That cannot be done before 7.1 as there
hasn't been any discussion. As soon as we have a branch for 7 and master will be for 7.1, I
will ping internals about that.

Cheers


Previous Comments:
------------------------------------------------------------------------
[2015-09-01 00:49:45] cmb@php.net

Point #2 has already been reported as bug #60632, and is currently
being addressed.

------------------------------------------------------------------------
[2015-08-22 17:51:39] totalfix at gmail dot com

Description:
------------
1) The function openssl_seal by default uses RC4 cipher, which is considered broken and should not
be used.
I believe it is not a best practice to leave a weak cipher as a default option as many non-experts
(like me) will use it.

2) Even if you want to change ciphers by using the parameter $method, you are limited to ciphers
without initialization vectors (so no AES CBC). This is leaves us with ciphers like AES ECB, which
is also not recommended.




Test script:
---------------
openssl_seal($data, $sealed, $ekeys, array($pk1), 'AES-256-CBC');

// this fails, because CBC cannot be used, this is not documented, so the users must use trial and
error to figure out which cipher is actually working

Expected result:
----------------
Somebody with cyrpto knowledge could read my text and decide if it's worth looking into. I
could be wrong, if so, I apologise in advance.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=70329&edit=1


Thread (3 messages)

« previous php.bugs (#195813) next »