Bug #77156 [NEW]: Useless warning for AEAD
| From: | obreham at gmail dot com | Date: | Wed, 14 Nov 2018 22:56:30 +0000 |
| Subject: | Bug #77156 [NEW]: Useless warning for AEAD | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-217962@lists.php.net to get a copy of this message | ||
From: obreham at gmail dot com
Operating system: Windows
PHP version: 7.1.24
Package: OpenSSL related
Bug Type: Bug
Bug description:Useless warning for AEAD
Description:
------------
PHP version: 7.1.9
The documentation for openssl_encrypt() indicates that the default &$tag
= NULL, which should be true for any case.
But if a $tag is deliberately passed - even when set to NULL - with a
cipher that does not support AEAD, a warning is triggered. This warning
is not even mentioned in the documentation.
There are no needs for this warning, especially when it is the default
value (NULL). The function does set the $tag to NULL (no matter its
initial value) and the correct encrypted data is returned. Nothing
unexpected happens.
As an aside, there is also a typo in the error message, it should read
"does not" and not "doesn not".
Test script:
---------------
$tag = null;
$encrypted = openssl_encrypt(
'data',
'aes-256-ctr',
'password',
0,
'1234567812345467',
$tag
);
var_dump($tag, $encrypted);
Expected result:
----------------
NULL
string(8) "/fQItQ=="
Actual result:
--------------
Warning: openssl_encrypt(): The authenticated tag cannot be provided
for cipher that doesn not support AEAD in C:\wamp\www\test\test.php on
line 8
NULL
string(8) "/fQItQ=="
--
Edit bug report at https://bugs.php.net/bug.php?id=77156&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=77156&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=77156&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=77156&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=77156&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=77156&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=77156&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=77156&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=77156&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=77156&r=support
Expected behavior: https://bugs.php.net/fix.php?id=77156&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=77156&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=77156&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=77156&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77156&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=77156&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=77156&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=77156&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=77156&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=77156&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=77156&r=mysqlcfg