Req #73432 [NEW]: openssl_error_string() returns empty for authentication error using GCM or CCM
| From: | enrico at zimuel dot it | Date: | Mon, 31 Oct 2016 17:07:30 +0000 |
| Subject: | Req #73432 [NEW]: openssl_error_string() returns empty for authentication error using GCM or CCM | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-205113@lists.php.net to get a copy of this message | ||
From: enrico at zimuel dot it
Operating system: Ubuntu
PHP version: 7.1.0RC5
Package: OpenSSL related
Bug Type: Feature/Change Request
Bug description:openssl_error_string() returns empty for authentication error using GCM or CCM
Description:
------------
I'm testing the new features of PHP 7.1 for the support of AEAD using
OpenSSL and I noticed that the openssl_error_string() returns an empty
string in case of authentication error. It will be nice to have a
message here to recognize this new case.
Test script:
---------------
$iv = random_bytes(openssl_cipher_iv_length('aes-256-gcm'));
$key = random_bytes(32);
$data = random_bytes(1024);
$ciphertext = openssl_encrypt($data, 'aes-256-gcm', $key,
OPENSSL_RAW_DATA, $iv, $tag);
// Change 1 bit in ciphertext
$i = rand(0, mb_strlen($ciphertext, '8bit') - 1);
$ciphertext[$i] = $ciphertext[$i] ^ chr(1);
$decrypt = openssl_decrypt($ciphertext, 'aes-256-gcm', $key,
OPENSSL_RAW_DATA, $iv, $tag);
if (false === $decrypt) {
printf("OpenSSL message: %s", openssl_error_string());
}
Expected result:
----------------
OpenSSL message: authentication error
Actual result:
--------------
OpenSSL message:
--
Edit bug report at https://bugs.php.net/bug.php?id=73432&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73432&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73432&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73432&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=73432&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=73432&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=73432&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=73432&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=73432&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=73432&r=support
Expected behavior: https://bugs.php.net/fix.php?id=73432&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=73432&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=73432&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=73432&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73432&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=73432&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=73432&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=73432&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=73432&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=73432&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=73432&r=mysqlcfg