Req #72247 [NEW]: There is no way to get key length for cipher algorithms

From: Date: Fri, 20 May 2016 02:46:12 +0000
Subject: Req #72247 [NEW]: There is no way to get key length for cipher algorithms
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201204@lists.php.net to get a copy of this message
From: S-sword at s-sword dot net Operating system: Windows10/CentOS7.2 PHP version: master-Git-2016-05-20 (Git) Package: OpenSSL related Bug Type: Feature/Change Request Bug description:There is no way to get key length for cipher algorithms Description: ------------ Current implementation of OpenSSL functions has openssl_cipher_iv_length, obtaining the initialize vector length for ciphers, but no way to get key length. Moreover, in the function openssl_encrypt, the argument $password is used simply as key and cut off if longer than algorithm specified max key length (see below example). Then it is insecure to pass the raw password to openssl_enctypt, so we want to apply PBKD; Password Based Key Derivation, in php implemented as Hash functions (hash_pbkdf2), but this algorithm requires the key length. This is why we cannot migrate from mcrypt to openssl (in mcrypt functions, mcrypt_get_key_size is defined). To summarize the above, we need the way to get max key length for cipher algorithms, like openssl_cipher_key_length. Test script: --------------- echo(openssl_encrypt('aaa', 'aes-256-cbc', str_pad('', 256, '0')).PHP_EOL); echo(openssl_encrypt('aaa', 'aes-256-cbc', str_pad('', 300, '0')).PHP_EOL); // These two code pass different passwords to openssl_encrypt but get same result. -- Edit bug report at https://bugs.php.net/bug.php?id=72247&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=72247&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=72247&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=72247&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=72247&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=72247&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=72247&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=72247&r=needscript Try newer version: https://bugs.php.net/fix.php?id=72247&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=72247&r=support Expected behavior: https://bugs.php.net/fix.php?id=72247&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=72247&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=72247&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=72247&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72247&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=72247&r=dst IIS Stability: https://bugs.php.net/fix.php?id=72247&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=72247&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=72247&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=72247&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=72247&r=mysqlcfg

« previous php.bugs (#201204) next »