Req #67304 [Asn->Csd]: openssl_decrypt fails with GCM mode
| From: | bukka@php.net | Date: | Sun, 19 Jun 2016 17:10:38 +0000 |
| Subject: | Req #67304 [Asn->Csd]: openssl_decrypt fails with GCM mode | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-201735@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67304&edit=1
ID: 67304
Updated by: bukka@php.net
Reported by: birki456 at hotmail dot com
Summary: openssl_decrypt fails with GCM mode
-Status: Assigned
+Status: Closed
Type: Feature/Change Request
Package: OpenSSL related
Operating System: all
PHP Version: 5.5.12
Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
Merged to master and will be part of 7.1
Previous Comments:
------------------------------------------------------------------------
[2016-04-28 14:02:04] florent at morselli dot fr
Hi,
I created a pure PHP library: https://packagist.org/packages/Spomky-Labs/php-aes-gcm
It works fine on PHP 5.4+, PHP 7.0+ and HHVM
------------------------------------------------------------------------
[2016-03-02 15:50:36] florent at morselli dot fr
Hi all,
If you cannot install PHP extension and your PHP version is not 7.1, you can encrypt using with GCM
mode in pure PHP.
This method is not as fast as the extension (approx 0.02 msec using the extension, 10 msec in pure
PHP), but will help you.
You can find an implementation of this mode here: https://github.com/Spomky-Labs/jose/blob/master/src/Util/GCM.php
```php
//Encryption
list($encrypted_cek, $tag) = GCM::encrypt($kek, $iv, $cek, $aad);
//Decryption
GCM::decrypt($kek, $iv, $encrypted_cek, $aad, $tag);
```
------------------------------------------------------------------------
[2016-03-02 15:01:09] albertcasademont at gmail dot com
This issue will be finally fixed in PHP 7.1
https://wiki.php.net/rfc/openssl_aead
------------------------------------------------------------------------
[2016-02-06 01:21:29] mcastelluccio at mozilla dot com
This is needed to implement the Web Push protocol in PHP: https://tools.ietf.org/html/draft-ietf-webpush-encryption-01
------------------------------------------------------------------------
[2015-12-04 20:48:32] lagrange dot louis at gmail dot com
If PHP was throwing an error when trying to use openssl_encrypt/decrypt with the cipher set to
'aes-xxx-gcm', I would agree with you that this is a feature request. But here this is
more of a bug since it just fail silently with openssl_decrypt and return the CTR with
openssl_encrypt...
If I can help to backport it to, say, 5.6, please let me know.
I'm already aware of your extension, but installing extensions is sadly not possible in every
installations (hosted servers for example).
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=67304
--
Edit this bug report at https://bugs.php.net/bug.php?id=67304&edit=1