Req #67304 [Com]: openssl_decrypt fails with GCM mode

From: Date: Thu, 28 Apr 2016 14:02:09 +0000
Subject: Req #67304 [Com]: openssl_decrypt fails with GCM mode
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200806@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67304&edit=1

 ID:                 67304
 Comment by:         florent at morselli dot fr
 Reported by:        birki456 at hotmail dot com
 Summary:            openssl_decrypt fails with GCM mode
 Status:             Assigned
 Type:               Feature/Change Request
 Package:            OpenSSL related
 Operating System:   all
 PHP Version:        5.5.12
 Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

Hi,

I created a pure PHP library: https://packagist.org/packages/Spomky-Labs/php-aes-gcm

It works fine on PHP 5.4+, PHP 7.0+ and HHVM


Previous Comments:
------------------------------------------------------------------------
[2016-03-02 15:50:36] florent at morselli dot fr

Hi all,

If you cannot install PHP extension and your PHP version is not 7.1, you can encrypt using with GCM
mode in pure PHP.
This method is not as fast as the extension (approx 0.02 msec using the extension, 10 msec in pure
PHP), but will help you.

You can find an implementation of this mode here: https://github.com/Spomky-Labs/jose/blob/master/src/Util/GCM.php

```php
//Encryption
list($encrypted_cek, $tag) = GCM::encrypt($kek, $iv, $cek, $aad);

//Decryption
GCM::decrypt($kek, $iv, $encrypted_cek, $aad, $tag);
```

------------------------------------------------------------------------
[2016-03-02 15:01:09] albertcasademont at gmail dot com

This issue will be finally fixed in PHP 7.1

https://wiki.php.net/rfc/openssl_aead

------------------------------------------------------------------------
[2016-02-06 01:21:29] mcastelluccio at mozilla dot com

This is needed to implement the Web Push protocol in PHP: https://tools.ietf.org/html/draft-ietf-webpush-encryption-01

------------------------------------------------------------------------
[2015-12-04 20:48:32] lagrange dot louis at gmail dot com

If PHP was throwing an error when trying to use openssl_encrypt/decrypt with the cipher set to
'aes-xxx-gcm', I would agree with you that this is a feature request. But here this is
more of a bug since it just fail silently with openssl_decrypt and return the CTR with
openssl_encrypt...

If I can help to backport it to, say, 5.6, please let me know.

I'm already aware of your extension, but installing extensions is sadly not possible in every
installations (hosted servers for example).

------------------------------------------------------------------------
[2015-12-04 19:15:05] bukka@php.net

This patch is just for master which means possibly next minor (7.1). Of course, if there are any
objections against it, then I will have to write RFC and it will have to pass to get in...

In any case I don't plan any back-port as the patch is relatively big for minor release
considering that this is not a bug but more a feature request.

If you need to use GCM in 5, you should take a look on my ext called crypto which already has full
support for GCM and CCM:

https://github.com/bukka/php-crypto

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=67304


--
Edit this bug report at https://bugs.php.net/bug.php?id=67304&edit=1


Thread (12 messages)

« previous php.bugs (#200806) next »