Bug #71917 [Opn->Asn]: openssl_open() returns junk on envelope < 16 bytes

From: Date: Tue, 25 Apr 2017 13:01:53 +0000
Subject: Bug #71917 [Opn->Asn]: openssl_open() returns junk on envelope < 16 bytes
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-208785@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71917&edit=1

 ID:                 71917
 Updated by:         bukka@php.net
 Reported by:        gelenkig at runbox dot com
 Summary:            openssl_open() returns junk on envelope < 16 bytes
-Status:             Open
+Status:             Assigned
 Type:               Bug
 Package:            OpenSSL related
 Operating System:   Linux
 PHP Version:        5.5.33
-Assigned To:        
+Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

So this is happening because openssl_encrypt automatically pads the key with \0 characters if
it's shorter then default key length. It's not an issue for fixed size ciphers (e.g. AES)
but for variable size ciphers like rc4 it could try first to set the key length which it does only
for longer keys (not shorter ones).

I have got a fix for that but I don't think we can add it to the bug fixing release as it could
cause issues for those relying on the fact that it will be filled with \0. I think that the safest
solution would be to introduce an option for that probably.


Previous Comments:
------------------------------------------------------------------------
[2016-03-29 12:19:05] gelenkig at runbox dot com

Description:
------------
OpenSSL provides two functions: openssl_seal and openssl_open which are basically just handy
shortcuts to manually:
- generating envelope key (CS-random string)
- encrypting it with public key
- encrypting data itself with that envelope key
- storing both encrypted data and encrypted envelope

One can successfully do this manually via openssl command line tool: i.e. encrypt envelope/data with
openssl cli and unseal with PHP or vice versa.

But PHP's openssl_open() seems to have a bug: it will return some junk instead of decrypted
plaintext if envelope's key is shorter than 16 bytes long. It will work fine if it's 16
bytes long or longer. Since openssl_seal() generates 128-bit key it's not a high-priority
problem but at least openssl_open() should emit a warning if for whatever the reason it's not
possible to fix the behaviour.

This was confirmed on RC4 cipher (default method).

Test script:
---------------
function test($envkey) {
  // $publicKey, $privateKey are OpenSSL Key resources.
  openssl_public_encrypt($envkey, $envelope, openssl_pkey_get_public($publicKey));
  $sealed = openssl_encrypt('plaintext', 'rc4', $envkey, OPENSSL_RAW_DATA);
  openssl_open($sealed, $output, $envelope, $privateKey, 'rc4');
  assert($output === 'plaintext');
}

// works - key of 16 bytes 
test('1234567890123456');
// fails - key of 15 bytes 
test('123456789012345');


Expected result:
----------------
openssl_open() should return original plaintext as long as supplied keys are correct, regardless of
the envelope key's length.

Actual result:
--------------
openssl_open() returns some junk with no warning or other indication if data was encrypted with
envelope key shorter than 16 bytes, at least if using RC4 cipher, even when given correct keys.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=71917&edit=1


Thread (4 messages)

« previous php.bugs (#208785) next »