Req #72247 [Opn->Ana]: There is no way to get key length for cipher algorithms

From: Date: Thu, 19 Sep 2019 01:55:11 +0000
Subject: Req #72247 [Opn->Ana]: There is no way to get key length for cipher algorithms
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222820@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72247&edit=1

 ID:                 72247
 Updated by:         bishop@php.net
 Reported by:        S-sword at s-sword dot net
 Summary:            There is no way to get key length for cipher
                     algorithms
-Status:             Open
+Status:             Analyzed
 Type:               Feature/Change Request
 Package:            OpenSSL related
 Operating System:   Windows10/CentOS7.2
 PHP Version:        master-Git-2016-05-20 (Git)
 Block user comment: N
 Private report:     N

 New Comment:

Key length available via either EVP_CIPHER_key_length or EVP_CIPHER_CTX_key_length. Would need to
decide if we're going to support variable length ciphers or not. Eg, a signature of:

openssl_get_key_length(string $cipher): int|false

or

openssl_get_key_length(string $cipher, string $encryption_mode): int|false


Previous Comments:
------------------------------------------------------------------------
[2016-05-20 02:46:09] S-sword at s-sword dot net

Description:
------------
Current implementation of OpenSSL functions has openssl_cipher_iv_length, obtaining the initialize
vector length for ciphers, but no way to get key length. 
Moreover, in the function openssl_encrypt, the argument $password is used simply as key and cut off
if longer than algorithm specified max key length (see below example). 
Then it is insecure to pass the raw password to openssl_enctypt, so we want to apply PBKD; Password
Based Key Derivation, in php implemented as Hash functions (hash_pbkdf2), but this algorithm
requires the key length.
This is why we cannot migrate from mcrypt to openssl (in mcrypt functions, mcrypt_get_key_size is
defined).

To summarize the above, we need the way to get max key length for cipher algorithms, like
openssl_cipher_key_length. 

Test script:
---------------
echo(openssl_encrypt('aaa', 'aes-256-cbc', str_pad('', 256,
'0')).PHP_EOL);
echo(openssl_encrypt('aaa', 'aes-256-cbc', str_pad('', 300,
'0')).PHP_EOL);

// These two code pass different passwords to openssl_encrypt but get same result. 



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=72247&edit=1


Thread (3 messages)

« previous php.bugs (#222820) next »