Bug #62102 [Opn->Csd]: mcrypt CAST128 80/40-bit does not agree with RFC2144 test vectors
| From: | leigh@php.net | Date: | Wed, 14 Dec 2016 17:55:17 +0000 |
| Subject: | Bug #62102 [Opn->Csd]: mcrypt CAST128 80/40-bit does not agree with RFC2144 test vectors | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-205998@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62102&edit=1
ID: 62102
Updated by: leigh@php.net
Reported by: nathanpust at hotmail dot com
Summary: mcrypt CAST128 80/40-bit does not agree with RFC2144
test vectors
-Status: Open
+Status: Closed
Type: Bug
Package: mcrypt related
Operating System: Windows XP
PHP Version: 5.3.13
-Assigned To:
+Assigned To: leigh
Block user comment: N
Private report: N
New Comment:
Closing as this was a bug in the underlying library (which was fixed) and the supplied test has
already been committed.
Previous Comments:
------------------------------------------------------------------------
[2014-10-16 04:26:50] gm dot outside+php at gmail dot com
This is just to let people know that there is a bug in the mcrypt 2.5.8 library and the library does
not support 80- and 40- bit keys. However, there is a Debian patch (one line patch, actually) that
fixes the issue: http://debian.2.n7.nabble.com/Bug-299509-libmcrypt-support-of-40-and-80-bits-long-keys-with-CAST5-td575143.html
Debian/Ubuntu has this patch incorporated, RHEL/CentOS/FC at this point of time do not. So the test
will pass on the distros where mcrypt has been fixed.
------------------------------------------------------------------------
[2014-03-04 19:49:30] narf at devilix dot net
I tried commenting earlier, not sure why my comment didn't show up ... this appears to have
been fixed. Both the OP's and my own tests produce the expected results (from RFC2144) on PHP
5.4, 5.5.
------------------------------------------------------------------------
[2012-05-22 01:54:16] nathanpust at hotmail dot com
Description:
------------
Please verify that the 80-bit and 40-bit test vectors in RFC2144 Section B.1 do
not agree with the output from mcrypt when using CAST 128 encryption. I provided
a test program with functions that print and parse the hexadecimal.
I am using mcrypt 2.5.8 on php 5.3.13.
The 128-bit test vector does work though. The problem is probably related to the
fact that CAST-128 changes the number of rounds from 16 to 12 when a key is 80
bits or smaller.
I have verified that the test vectors in RFC2144 work with a different piece of
code written in C.
Please let me know if there is a work around.
Test script:
---------------
function str2hex($string)
{
$hex='';
for ($i=0; $i < strlen($string); $i++)
{
$hex .= sprintf("%02x",ord($string[$i])) . ' ';
}
return $hex;
}
function hex2str($x) {
$s='';
foreach(explode("\n",trim(chunk_split($x,2))) as $h) $s.=chr(hexdec($h));
return($s);
}
//RFC-2144
$text = hex2str("0123456789ABCDEF");
//Section B.1 128-bit example
$key = hex2str("0123456712345678234567893456789A");
echo "RFC-2144 Section B.1 128-bit<BR>";
$enc = mcrypt_encrypt(MCRYPT_CAST_128,$key,$text,MCRYPT_MODE_ECB);
echo "ciphertext: " . str2hex($enc);
echo "<BR>";
//RFC-2144
//Section B.1 80-bit example
$key = hex2str("01234567123456782345");
echo "RFC-2144 Section B.1 80-bit<BR>";
$enc = mcrypt_encrypt(MCRYPT_CAST_128,$key,$text,MCRYPT_MODE_ECB);
echo "ciphertext: " . str2hex($enc);
echo "<BR>";
//RFC-2144
//Section B.1 40-bit example
$key = hex2str("0123456712");
echo "RFC-2144 Section B.1 40-bit<BR>";
$enc = mcrypt_encrypt(MCRYPT_CAST_128,$key,$text,MCRYPT_MODE_ECB);
echo "ciphertext: " . str2hex($enc);
echo "<BR>";
Expected result:
----------------
see RFC2144 Section B.1
Actual result:
--------------
see result of provided code.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=62102&edit=1