Bug #73808 [Opn->Asn]: iv length warning too restrictive for aes-128-ccm

From: Date: Sun, 30 Apr 2017 18:37:11 +0000
Subject: Bug #73808 [Opn->Asn]: iv length warning too restrictive for aes-128-ccm
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-208873@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73808&edit=1 ID: 73808 Updated by: bukka@php.net Reported by: anthon dot pang at gmail dot com -Summary: iv length check too restrictive for aes-128-ccm +Summary: iv length warning too restrictive for aes-128-ccm -Status: Open +Status: Assigned Type: Bug Package: OpenSSL related PHP Version: 7.1.0 -Assigned To: +Assigned To: bukka Block user comment: N Private report: N New Comment: IV length can be set. You can try var_dump(openssl_encrypt('data', 'aes-256-ccm', 'password', 0, '1234567', $tag)); or just see https://3v4l.org/5Vdo3 The only thing that is wrong is a warning that specifies default length which doesn't make much sense because it can be a range so the message should be definitely stripped. I'll fix it as part of this bug (that's why I renamed it...) Previous Comments: ------------------------------------------------------------------------ [2016-12-28 12:00:25] anthon dot pang at gmail dot com Just for comparison, sjcl appears to silently truncate iv when length > 13. ------------------------------------------------------------------------ [2016-12-23 19:23:07] anthon dot pang at gmail dot com Description: ------------ openssl_decrypt with a cipher of 'aes-128-ccm' currently enforces an iv length of 12 octets or 96 bits. According to various RFCs, the iv length has an allowable range of 7 to 13 octets. https://tools.ietf.org/html/rfc3610 https://tools.ietf.org/html/rfc5084 "aes-nonce OCTET STRING (SIZE(7..13))," Expected result: ---------------- In php_openssl_validate_iv(), when mode->is_aead, treat iv_required_len as a recommendation; do a range check instead. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73808&edit=1

« previous php.bugs (#208873) next »