Bug #73463 [Opn]: openssl_encrypt aes-128-gcm fails

From: Date: Wed, 09 Nov 2016 11:49:23 +0000
Subject: Bug #73463 [Opn]: openssl_encrypt aes-128-gcm fails
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205254@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73463&edit=1 ID: 73463 Updated by: bukka@php.net Reported by: mjones@php.net Summary: openssl_encrypt aes-128-gcm fails Status: Open Type: Bug Package: OpenSSL related Operating System: Ubuntu PHP Version: 7.1.0RC5 Block user comment: N Private report: N New Comment: Closing as this is duplicate already fixed bug. See https://wiki.php.net/rfc/openssl_aead for more info Previous Comments: ------------------------------------------------------------------------ [2016-11-04 21:45:07] mjones@php.net Description: ------------ openssl_decrypt fails to decrypt the result from openssl_encrypt for GCM based authenticated encryption methods supported in openssl like 'aes-128-gcm'. The below example works for aes-128-cbc and other cipher methods, but not 'aes-128-gcm','aes-192-gcm','aes-256-gcm', despite all of those being listed as supported in openssl_get_cipher_methods(). The reason it fails, is because openssl_encrypt does not insert the "authenticated encryption tag" into the encrypted string. This affects PHP 5.6, 7.0, 7.1.0RC5. Test script: --------------- <?php $methods = openssl_get_cipher_methods(); $method='aes-128-gcm'; //$method='aes-128-cbc'; $data = 'junk data'; $key = openssl_random_pseudo_bytes(16); $iv = openssl_random_pseudo_bytes(openssl_cipher_iv_length($method)); $encrypted = openssl_encrypt($data, $method, $key, $options=0, $iv); $decrypted = openssl_decrypt($encrypted, $method, $key, $options=0, $iv); echo $data."\n"; echo $encrypted."\n"; echo $decrypted."\n"; Expected result: ---------------- junk data iu8Ijn2SndGXJll4qpxLWL0rsEsTiNoAMw== junk data Actual result: -------------- junk data iu8Ijn2SndGX ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73463&edit=1

« previous php.bugs (#205254) next »