Req #67304 [Opn->Asn]: openssl_decrypt fails with GCM mode

From: Date: Thu, 03 Dec 2015 23:17:07 +0000
Subject: Req #67304 [Opn->Asn]: openssl_decrypt fails with GCM mode
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197575@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67304&edit=1 ID: 67304 Updated by: bukka@php.net Reported by: birki456 at hotmail dot com Summary: openssl_decrypt fails with GCM mode -Status: Open +Status: Assigned Type: Feature/Change Request Package: OpenSSL related Operating System: all PHP Version: 5.5.12 -Assigned To: +Assigned To: bukka Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2015-11-16 13:38:29] albertcasademont at gmail dot com This would be indeed very useful. Right now we have to do it in 2 steps with an hmac ------------------------------------------------------------------------ [2014-05-19 17:00:18] birki456 at hotmail dot com Description: ------------ While the gcm mode (which is authenticated encryption) is reported in openssl_get_cipher_methods() (e.g. [106] => aes-256-gcm), neither openssl_encrypt nor openssl_decrypt support it. There simply is no code to supply/return the authentication tag. It should be fairly simple to add however it possibly requires a change of the return type, because ciphertext and tag need to be returned in the encryption case and ciphertext and tag need to be supplied for decryption. It should also be possible to distinguish between decryption failure due to authentication failure vs. other failure. The code below *should*, as last line, print 'recovered: Hello World', however decryption with gcm always fails. Test script: --------------- echo print_r(openssl_get_cipher_methods(), true); $cipher = 'aes-256-gcm'; $ivlen = openssl_cipher_iv_length($cipher); echo "iv len: " . $ivlen . "\n"; $iv = openssl_random_pseudo_bytes($ivlen); $hexiv = bin2hex($iv); echo "iv: " . $hexiv . "\n"; $plaintext = "Hello World"; echo "plaintext: " . $plaintext . "\n"; $clearpass = 'passphrase'; $pbkdfsalt = openssl_random_pseudo_bytes(16); $password = hash_pbkdf2('sha256', $clearpass, $pbkdfsalt, 1001, 32, true); echo "clearpass: " . $clearpass . "\n"; echo "pbkdfsalt: " . bin2hex($pbkdfsalt) . "\n"; echo "password: " . bin2hex($password) . "\n"; // This is the important part: $ciphertext = openssl_encrypt($plaintext, $cipher, $password, 0, $iv); echo "ciphertext: " . print_r($ciphertext, true) . "\n"; $recovered = openssl_decrypt($ciphertext, $cipher, $password, 0, $iv); echo "recovered: " . $recovered . "\n"; ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67304&edit=1

« previous php.bugs (#197575) next »