Req #74375 [Wfx]: Allow installation of pecl/mcrypt on PHP 7.1
| From: | requinix@php.net | Date: | Wed, 05 Apr 2017 16:23:38 +0000 |
| Subject: | Req #74375 [Wfx]: Allow installation of pecl/mcrypt on PHP 7.1 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-208342@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74375&edit=1
ID: 74375
Updated by: requinix@php.net
Reported by: ramsey@php.net
Summary: Allow installation of pecl/mcrypt on PHP 7.1
Status: Wont fix
Type: Feature/Change Request
Package: mcrypt related
PHP Version: 7.1.3
Block user comment: N
Private report: N
New Comment:
It will be removed from the core in 7.2. mcrypt is deprecated because it's dead - the move to
PECL is so people can get to it if they still need it.
https://wiki.php.net/rfc/mcrypt-viking-funeral
Previous Comments:
------------------------------------------------------------------------
[2017-04-05 16:21:06] spam2 at rhsoft dot net
why move them to PECL - because if you ever find data enrcypted with php-mcrypt they are otherwise
lost forever?
https://paragonie.com/blog/2015/05/if-you-re-typing-word-mcrypt-into-your-code-you-re-doing-it-wrong
Surprise! MCRYPT_RIJNDAEL_256 doesn't mean AES-256.
All variants of AES use a 128-bit block size with varying key lengths (128, 192, or 256). This means
that MCRYPT_RIJNDAEL_128 is the only correct choice if you want AES.
------------------------------------------------------------------------
[2017-04-05 16:04:07] ramsey@php.net
Why move them to PECL if they're deprecated?
------------------------------------------------------------------------
[2017-04-05 15:38:41] nikic@php.net
The mcrypt functions in the PECL extension are also deprecated -- it doesn't matter whether you
use the bundled or PECL variant. As such, I'm marking this as won't fix.
------------------------------------------------------------------------
[2017-04-05 15:31:50] ramsey@php.net
Description:
------------
(The "package affected" should be "PECL > mcrypt," but that doesn't
exist yet in the dropdown.)
PHP 7.1 generates deprecation warnings for mcrypt functions. I would like to build PHP 7.1 without
mcrypt and install the PECL extension to avoid these warnings and prepare for PHP 7.2. However,
pecl/mcrypt has a minimum requirement of PHP 7.2.0.
Please change the pecl/mcrypt minimum requirement to 7.1.0 to allow users to migrate to the PECL
extension before the release of 7.2.0.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74375&edit=1