Bug #73808 [Opn->Asn]: iv length warning too restrictive for aes-128-ccm
| From: | bukka@php.net | Date: | Sun, 30 Apr 2017 18:37:11 +0000 |
| Subject: | Bug #73808 [Opn->Asn]: iv length warning too restrictive for aes-128-ccm | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-208873@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73808&edit=1
ID: 73808
Updated by: bukka@php.net
Reported by: anthon dot pang at gmail dot com
-Summary: iv length check too restrictive for aes-128-ccm
+Summary: iv length warning too restrictive for aes-128-ccm
-Status: Open
+Status: Assigned
Type: Bug
Package: OpenSSL related
PHP Version: 7.1.0
-Assigned To:
+Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
IV length can be set. You can try
var_dump(openssl_encrypt('data', 'aes-256-ccm', 'password', 0,
'1234567', $tag));
or just see https://3v4l.org/5Vdo3
The only thing that is wrong is a warning that specifies default length which doesn't make much
sense because it can be a range so the message should be definitely stripped. I'll fix it as
part of this bug (that's why I renamed it...)
Previous Comments:
------------------------------------------------------------------------
[2016-12-28 12:00:25] anthon dot pang at gmail dot com
Just for comparison, sjcl appears to silently truncate iv when length > 13.
------------------------------------------------------------------------
[2016-12-23 19:23:07] anthon dot pang at gmail dot com
Description:
------------
openssl_decrypt with a cipher of 'aes-128-ccm' currently enforces an iv length of 12
octets or 96 bits. According to various RFCs, the iv length has an allowable range of 7 to 13
octets.
https://tools.ietf.org/html/rfc3610
https://tools.ietf.org/html/rfc5084
"aes-nonce OCTET STRING (SIZE(7..13)),"
Expected result:
----------------
In php_openssl_validate_iv(), when mode->is_aead, treat iv_required_len as a recommendation; do a
range check instead.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73808&edit=1