Req #67304 [Com]: openssl_decrypt fails with GCM mode

From: Date: Fri, 04 Dec 2015 20:48:33 +0000
Subject: Req #67304 [Com]: openssl_decrypt fails with GCM mode
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197597@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67304&edit=1

 ID:                 67304
 Comment by:         lagrange dot louis at gmail dot com
 Reported by:        birki456 at hotmail dot com
 Summary:            openssl_decrypt fails with GCM mode
 Status:             Assigned
 Type:               Feature/Change Request
 Package:            OpenSSL related
 Operating System:   all
 PHP Version:        5.5.12
 Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

If PHP was throwing an error when trying to use openssl_encrypt/decrypt with the cipher set to
'aes-xxx-gcm', I would agree with you that this is a feature request. But here this is
more of a bug since it just fail silently with openssl_decrypt and return the CTR with
openssl_encrypt...

If I can help to backport it to, say, 5.6, please let me know.

I'm already aware of your extension, but installing extensions is sadly not possible in every
installations (hosted servers for example).


Previous Comments:
------------------------------------------------------------------------
[2015-12-04 19:15:05] bukka@php.net

This patch is just for master which means possibly next minor (7.1). Of course, if there are any
objections against it, then I will have to write RFC and it will have to pass to get in...

In any case I don't plan any back-port as the patch is relatively big for minor release
considering that this is not a bug but more a feature request.

If you need to use GCM in 5, you should take a look on my ext called crypto which already has full
support for GCM and CCM:

https://github.com/bukka/php-crypto

------------------------------------------------------------------------
[2015-12-04 18:57:23] lagrange dot louis at gmail dot com

Good news, thanks @bukka!
Do you know in which branches this will be merged? (hopefully a 5.x branch)

------------------------------------------------------------------------
[2015-12-03 23:25:07] bukka@php.net

I have been slowly working on it and should be hopefuly ready for 7.1:

The progress can be seen here:

https://github.com/php/php-src/compare/master...bukka:openssl_aead

------------------------------------------------------------------------
[2015-11-16 13:38:29] albertcasademont at gmail dot com

This would be indeed very useful. Right now we have to do it in 2 steps with an hmac

------------------------------------------------------------------------
[2014-05-19 17:00:18] birki456 at hotmail dot com

Description:
------------
While the gcm mode (which is authenticated encryption) is reported in openssl_get_cipher_methods()
(e.g. [106] => aes-256-gcm), neither openssl_encrypt nor openssl_decrypt support it. There simply
is no code to supply/return the authentication tag. It should be fairly simple to add however it
possibly requires a change of the return type, because ciphertext and tag need to be returned in the
encryption case and ciphertext and tag need to be supplied for decryption. It should also be
possible to distinguish between decryption failure due to authentication failure vs. other failure.

The code below *should*, as last line, print 'recovered: Hello World', however decryption
with gcm always fails.

Test script:
---------------
echo print_r(openssl_get_cipher_methods(), true);

$cipher = 'aes-256-gcm';

$ivlen = openssl_cipher_iv_length($cipher);

echo "iv len: " . $ivlen . "\n";

$iv = openssl_random_pseudo_bytes($ivlen);
$hexiv = bin2hex($iv);

echo "iv: " . $hexiv . "\n";

$plaintext = "Hello World";

echo "plaintext: " . $plaintext . "\n";

$clearpass = 'passphrase';
$pbkdfsalt = openssl_random_pseudo_bytes(16);
$password = hash_pbkdf2('sha256', $clearpass, $pbkdfsalt, 1001, 32, true);

echo "clearpass: " . $clearpass . "\n";
echo "pbkdfsalt: " . bin2hex($pbkdfsalt) . "\n";
echo "password: " . bin2hex($password) . "\n";

// This is the important part:
$ciphertext = openssl_encrypt($plaintext, $cipher, $password, 0, $iv);

echo "ciphertext: " . print_r($ciphertext, true) . "\n";

$recovered = openssl_decrypt($ciphertext, $cipher, $password, 0, $iv);

echo "recovered: " . $recovered . "\n";




------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=67304&edit=1


Thread (12 messages)

« previous php.bugs (#197597) next »