Req #76935 [NEW]: "chacha20-poly1305" is an AEAD but does not work like AEAD
| From: | patrakov at gmail dot com | Date: | Wed, 26 Sep 2018 09:05:29 +0000 |
| Subject: | Req #76935 [NEW]: "chacha20-poly1305" is an AEAD but does not work like AEAD | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-217244@lists.php.net to get a copy of this message | ||
From: patrakov at gmail dot com
Operating system: Linux
PHP version: 7.2.10
Package: OpenSSL related
Bug Type: Feature/Change Request
Bug description:"chacha20-poly1305" is an AEAD but does not work like AEAD
Description:
------------
"chacha20-poly1305" is listed in the result of
openssl_get_cipher_methods(). Wikipedia says it is an AEAD. I.e., if I
call openssl_encrypt and provide a reference to a variable that is
supposed to get the authentication tag, I expect it to get the tag.
Instead, I get this warning:
PHP Warning: openssl_encrypt(): The authenticated tag cannot be
provided for cipher that doesn not support AEAD in
/home/aep/aead-test/index.php on line 17
There is a pure PHP implementation of chacha20-poly1305, and it does
support the AEAD mode (i.e. gets a tag). It is available as
"leigh/aead-chacha20-poly1305" via composer, and the test script below
uses it for reference.
Test script:
---------------
<?php
# make sure that you used Composer to get
"leigh/aead-chacha20-poly1305"
require __DIR__ . '/vendor/autoload.php';
$key = str_repeat('k', 32);
$nonce = str_repeat('n', 12);
$plaintext = '12345678';
$aad = '';
list($ciphertext, $tag) = \ChaCha20Poly1305\encrypt($key, $nonce, $aad,
$plaintext);
$cl = implode(unpack("H*", $ciphertext));
$tl = implode(unpack("H*", $tag));
print("Pure PHP\n");
print("Ciphertext: $cl, tag: $tl\n");
$openssl_ct = openssl_encrypt($plaintext, "chacha20-poly1305", $key,
OPENSSL_RAW_DATA, $nonce, $openssl_tag, $aad);
$ocl = implode(unpack("H*", $openssl_ct));
$otl = implode(unpack("H*", $openssl_tag));
print("OpenSSL\n");
print("Ciphertext: $ocl, tag: $otl\n");
Expected result:
----------------
Pure PHP
Ciphertext: bfcd0d66f7e49c21, tag: e48864c53c4deb83bcee96add54ef851
OpenSSL
Ciphertext: bfcd0d66f7e49c21, tag: e48864c53c4deb83bcee96add54ef851
Actual result:
--------------
Pure PHP
Ciphertext: bfcd0d66f7e49c21, tag: e48864c53c4deb83bcee96add54ef851
PHP Warning: openssl_encrypt(): The authenticated tag cannot be
provided for cipher that doesn not support AEAD in
/home/aep/aead-test/index.php on line 17
OpenSSL
Ciphertext: bfcd0d66f7e49c21, tag:
--
Edit bug report at https://bugs.php.net/bug.php?id=76935&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=76935&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=76935&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=76935&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=76935&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=76935&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=76935&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=76935&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=76935&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=76935&r=support
Expected behavior: https://bugs.php.net/fix.php?id=76935&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=76935&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=76935&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=76935&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=76935&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=76935&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=76935&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=76935&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=76935&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=76935&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=76935&r=mysqlcfg