Bug #73463 [NEW]: openssl_encrypt aes-128-gcm fails
| From: | mjones@php.net | Date: | Fri, 04 Nov 2016 21:45:07 +0000 |
| Subject: | Bug #73463 [NEW]: openssl_encrypt aes-128-gcm fails | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-205191@lists.php.net to get a copy of this message | ||
From: mjones
Operating system: Ubuntu
PHP version: 7.1.0RC5
Package: OpenSSL related
Bug Type: Bug
Bug description:openssl_encrypt aes-128-gcm fails
Description:
------------
openssl_decrypt fails to decrypt the result from openssl_encrypt for GCM
based authenticated encryption methods supported in openssl like
'aes-128-gcm'.
The below example works for aes-128-cbc and other cipher methods, but
not 'aes-128-gcm','aes-192-gcm','aes-256-gcm', despite all of those
being listed as supported in openssl_get_cipher_methods().
The reason it fails, is because openssl_encrypt does not insert the
"authenticated encryption tag" into the encrypted string.
This affects PHP 5.6, 7.0, 7.1.0RC5.
Test script:
---------------
<?php
$methods = openssl_get_cipher_methods();
$method='aes-128-gcm';
//$method='aes-128-cbc';
$data = 'junk data';
$key = openssl_random_pseudo_bytes(16);
$iv = openssl_random_pseudo_bytes(openssl_cipher_iv_length($method));
$encrypted = openssl_encrypt($data, $method, $key, $options=0, $iv);
$decrypted = openssl_decrypt($encrypted, $method, $key, $options=0,
$iv);
echo $data."\n";
echo $encrypted."\n";
echo $decrypted."\n";
Expected result:
----------------
junk data
iu8Ijn2SndGXJll4qpxLWL0rsEsTiNoAMw==
junk data
Actual result:
--------------
junk data
iu8Ijn2SndGX
--
Edit bug report at https://bugs.php.net/bug.php?id=73463&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73463&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73463&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73463&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=73463&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=73463&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=73463&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=73463&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=73463&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=73463&r=support
Expected behavior: https://bugs.php.net/fix.php?id=73463&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=73463&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=73463&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=73463&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73463&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=73463&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=73463&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=73463&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=73463&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=73463&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=73463&r=mysqlcfg