Bug #75407 [Opn->Fbk]: No warning thrown for a nonexistant cipher method

From: Date: Thu, 19 Oct 2017 12:03:36 +0000
Subject: Bug #75407 [Opn->Fbk]: No warning thrown for a nonexistant cipher method
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-211778@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75407&edit=1

 ID:                 75407
 Updated by:         peehaa@php.net
 Reported by:        faxitnow at yahoo dot ca
 Summary:            No warning thrown for a nonexistant cipher method
-Status:             Open
+Status:             Feedback
 Type:               Bug
 Package:            OpenSSL related
 PHP Version:        Irrelevant
 Block user comment: N
 Private report:     N

 New Comment:

When I do check the supported cipher methods in both my install as on 3v4l I see it listed.

https://3v4l.org/j7gWD

Are you saying it's not listed for you and it doesn't give you an error?


Previous Comments:
------------------------------------------------------------------------
[2017-10-19 11:48:26] faxitnow at yahoo dot ca

Description:
------------
Using $encrypted = openssl_encrypt($dataEncrypt, "AES-256-XTS", $key, 0, $iv);

Does not throw a warning for a nonexistant cipher method. However, when replacing the "S"
with a "C" for example such as "AES-256-XTC" or any letter from the alphabet
other than "S" (A to Z except S) does throw a warning such as:

Warning: openssl_encrypt(): Unknown cipher algorithm in path/to/file.php on line X


Test script:
---------------
$key = hash_hmac("sha512", "You can decrypt this all day long, won't get you
closer to the truth", "myKey");
$iv = openssl_random_pseudo_bytes(16);
$adminVal = filter_var($userData['is_admin'], FILTER_VALIDATE_BOOLEAN);
$userName = $userData["name"];
$dataEncrypt = $adminVal.$userName;
$encrypted = openssl_encrypt($dataEncrypt, "AES-256-XTS", $key, 0, $iv);

As per a question posted on Stack Overflow at the following URL: 
https://stackoverflow.com/q/46821439/


Expected result:
----------------
The expected result should have thrown a warning such as:
Warning: openssl_encrypt(): Unknown cipher algorithm in path/to/file.php on line X

Actual result:
--------------
No warning thrown, just an empty result. 
string(0) "" when using var_dump($encrypted); from the test script included.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=75407&edit=1


Thread (8 messages)

« previous php.bugs (#211778) next »