Req #73651 [NEW]: mcrypt being deprecated without suitable alternative
| From: | magicaltux at gmail dot com | Date: | Mon, 05 Dec 2016 06:11:54 +0000 |
| Subject: | Req #73651 [NEW]: mcrypt being deprecated without suitable alternative | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-205767@lists.php.net to get a copy of this message | ||
From: magicaltux at gmail dot com
Operating system: Linux
PHP version: 7.1.0
Package: mcrypt related
Bug Type: Feature/Change Request
Bug description:mcrypt being deprecated without suitable alternative
Description:
------------
As per PHP rfc https://wiki.php.net/rfc/mcrypt-viking-funeral
mcrypt is
being deprecated, being unmaintained since 2007 and probably containing
quite a few bugs.
The RFC states:
> Everything libmcrypt can do, openssl can do too (and often better),
either out-of-the-box or via its support for pluggable ciphers.
This is however not true. I am writing this because we currently use
mcrypt here for a few things and OpenSSL does not work as an alternative
to mcrypt.
More specifically low level control on the encryption allows
encryption/decryption of streams, either manually (via
mcrypt_generic_init) or PHP streams (see
http://php.net/manual/en/filters.encryption.php
)
There is currently no suitable alternative in OpenSSL or any bundled
extension for encryption of streams (over tcp or in order to process
large volumes of data) and while it is likely possible to write a PHP
native implementation of AES and others, it would lead to a large loss
in terms of performances.
I have no objection to see mcrypt disappear in exchange for something
else, however there is currently no alternative except using
implementations such as phpseclib which have both native code and use
tricks to have OpenSSL handle streams of data. Having a clean
implementation with PHP filters (or without, that's fine too) would be
useful.
--
Edit bug report at https://bugs.php.net/bug.php?id=73651&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73651&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73651&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73651&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=73651&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=73651&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=73651&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=73651&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=73651&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=73651&r=support
Expected behavior: https://bugs.php.net/fix.php?id=73651&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=73651&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=73651&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=73651&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73651&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=73651&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=73651&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=73651&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=73651&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=73651&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=73651&r=mysqlcfg