Req #72247 [NEW]: There is no way to get key length for cipher algorithms
| From: | S-sword at s-sword dot net | Date: | Fri, 20 May 2016 02:46:12 +0000 |
| Subject: | Req #72247 [NEW]: There is no way to get key length for cipher algorithms | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-201204@lists.php.net to get a copy of this message | ||
From: S-sword at s-sword dot net
Operating system: Windows10/CentOS7.2
PHP version: master-Git-2016-05-20 (Git)
Package: OpenSSL related
Bug Type: Feature/Change Request
Bug description:There is no way to get key length for cipher algorithms
Description:
------------
Current implementation of OpenSSL functions has
openssl_cipher_iv_length, obtaining the initialize vector length for
ciphers, but no way to get key length.
Moreover, in the function openssl_encrypt, the argument $password is
used simply as key and cut off if longer than algorithm specified max
key length (see below example).
Then it is insecure to pass the raw password to openssl_enctypt, so we
want to apply PBKD; Password Based Key Derivation, in php implemented as
Hash functions (hash_pbkdf2), but this algorithm requires the key
length.
This is why we cannot migrate from mcrypt to openssl (in mcrypt
functions, mcrypt_get_key_size is defined).
To summarize the above, we need the way to get max key length for cipher
algorithms, like openssl_cipher_key_length.
Test script:
---------------
echo(openssl_encrypt('aaa', 'aes-256-cbc', str_pad('', 256,
'0')).PHP_EOL);
echo(openssl_encrypt('aaa', 'aes-256-cbc', str_pad('', 300,
'0')).PHP_EOL);
// These two code pass different passwords to openssl_encrypt but get
same result.
--
Edit bug report at https://bugs.php.net/bug.php?id=72247&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=72247&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=72247&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=72247&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=72247&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=72247&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=72247&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=72247&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=72247&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=72247&r=support
Expected behavior: https://bugs.php.net/fix.php?id=72247&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=72247&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=72247&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=72247&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72247&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=72247&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=72247&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=72247&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=72247&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=72247&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=72247&r=mysqlcfg