Bug #73812 [Nab]: openssl_error_string() dubious when decrypting aes-128-ccm

From: Date: Mon, 16 Jan 2017 03:29:46 +0000
Subject: Bug #73812 [Nab]: openssl_error_string() dubious when decrypting aes-128-ccm
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206642@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73812&edit=1

 ID:                 73812
 User updated by:    anthon dot pang at gmail dot com
 Reported by:        anthon dot pang at gmail dot com
 Summary:            openssl_error_string() dubious when decrypting
                     aes-128-ccm
 Status:             Not a bug
 Type:               Bug
 Package:            OpenSSL related
 PHP Version:        7.1.0
 Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

What are we missing here?

I got the same warning when I changed $password to a 16 character string; and $digest is a hash, so
it's always a 32 byte string.

<?php
$password = 'passwordpassword';
$input    =
json_decode('{"iv":"A0DOQPxWAlJ5LHjoyg==","v":1,"iter":10000,"ks":128,"ts":64,"mode":"ccm","adata":"","cipher":"aes","salt":"iGC2RaDrxUk=","ct":"3X3DKTIIE0VN0SzC9gH8k4wK3DNAsA=="}',
true);
$digest   = hash_pbkdf2('sha256', $password, base64_decode($input['salt']),
$input['iter'], 0, true);
$cipher   = $input['cipher'] . '-' . $input['ks'] . '-' .
$input['mode'];
$ct       = substr(base64_decode($input['ct']), 0, - $input['ts'] / 8);
$tag      = substr(base64_decode($input['ct']), - $input['ts'] / 8);
$iv       = base64_decode($input['iv']);
$adata    = $input['adata'];

$dt = openssl_decrypt($ct, $cipher, $digest, OPENSSL_RAW_DATA, $iv, $tag, $adata);
var_dump($dt);
while ($msg = openssl_error_string()) {
    echo $msg . "\n";
}


Previous Comments:
------------------------------------------------------------------------
[2017-01-15 21:19:05] bukka@php.net

Actually missed that you pass digest. In that case it means that $digest needs to be 16 bytes
(strlen($digest) === 16)... ;)

------------------------------------------------------------------------
[2017-01-15 21:16:30] bukka@php.net

I mean that in your example $password needs to by 16 bytes (128 bits as it's the block size of
aes-128)

------------------------------------------------------------------------
[2017-01-09 20:12:39] anthon dot pang at gmail dot com

In the context of my example, do you mean $password or $digest needs to match the block length?

------------------------------------------------------------------------
[2017-01-09 18:53:16] bukka@php.net

Yeah this is expected. It is due to fact that you supplied password that doesn't match the
exact block length so it's either filled with 0 bytes (if short) or trimmed (if long). This
behaviour cannot be changed due to BC concern.

------------------------------------------------------------------------
[2016-12-25 19:04:16] anthon dot pang at gmail dot com

Description:
------------
openssl_error_string() returns a dubious message, "error:0607A082:digital envelope
routines:EVP_CIPHER_CTX_set_key_length:invalid key length" when decrypting even though the
payload was successfully decrypted

(In the test script, the payload was produced using sjcl.)


Test script:
---------------
<?php
$password = 'password';
$input    =
json_decode('{"iv":"A0DOQPxWAlJ5LHjoyg==","v":1,"iter":1000,"ks":128,"ts":64,"mode":"ccm","adata":"","cipher":"aes","salt":"Kk+ws1Xj0Xo=","ct":"NCPpLCHLLO5mBOGpSUpHdXPgKZA="}',
true);
$digest   = hash_pbkdf2('sha256', $password, base64_decode($input['salt']),
$input['iter'], 0, true);
$cipher   = $input['cipher'] . '-' . $input['ks'] . '-' .
$input['mode'];
$ct       = substr(base64_decode($input['ct']), 0, - $input['ts'] / 8);
$tag      = substr(base64_decode($input['ct']), - $input['ts'] / 8);
$iv       = base64_decode($input['iv']);
$adata    = $input['adata'];

$dt = openssl_decrypt($ct, $cipher, $digest, OPENSSL_RAW_DATA, $iv, $tag, $adata);
var_dump($dt);
while ($msg = openssl_error_string()) {
    echo $msg . "\n";
}

Expected result:
----------------
string(12) "Hello World!"


Actual result:
--------------
string(12) "Hello World!"
error:0607A082:digital envelope routines:EVP_CIPHER_CTX_set_key_length:invalid key length


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=73812&edit=1


Thread (5 messages)

« previous php.bugs (#206642) next »