Bug #79983 [NEW]: openssl_encrypt / openssl_decrypt fail with OCB mode

From: Date: Sun, 16 Aug 2020 21:06:41 +0000
Subject: Bug #79983 [NEW]: openssl_encrypt / openssl_decrypt fail with OCB mode
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-228618@lists.php.net to get a copy of this message
From:             bizxing at web dot de
Operating system: Win 10
PHP version:      Irrelevant
Package:          OpenSSL related
Bug Type:         Bug
Bug description:openssl_encrypt / openssl_decrypt fail with OCB mode

Description:
------------
Although the OCB mode (authenticated encryption) is included in the list
of available algorithms (e.g. [33] => aes-256-ocb) it is not properly
supported. openssl_encrypt causes the error message: >The authenticated
tag cannot be provided for cipher that doesn not support AEAD<. No tag
is provided. However, the generated ciphertext seems to be correct.
openssl_decrypt returns false. If aes-256-ocb is replaced by e.g.
aes-256-gcm, it works as expected.


Test script:
---------------
//echo print_r(openssl_get_cipher_methods(), true);

$plaintext = "The quick brown fox jumps over the lazy dog";
$cipher = 'aes-256-ocb';
$key = '01234567890123456789012345678901';
$iv = '012345678901';

$ciphertext = openssl_encrypt($plaintext, $cipher, $key,
OPENSSL_RAW_DATA, $iv, $tag);
echo "tag (hex): " . bin2hex($tag) . PHP_EOL ;
echo "ciphertext (hex): " . bin2hex($ciphertext) . PHP_EOL ;

$recovered = openssl_decrypt($ciphertext, $cipher, $key,
OPENSSL_RAW_DATA, $iv, $tag);
echo "recovered: " . ($recovered == false ? 'false' : $recovered) .
PHP_EOL ;


Expected result:
----------------
For the OCB mode, analogous to the GCM/CCM mode, a tag should be
generated during encryption (6th parameter, $tag), which is used for
authentication during decryption. 

Actual result:
--------------
See description / test script

-- 
Edit bug report at https://bugs.php.net/bug.php?id=79983&edit=1
-- 
Fix committed:                    https://bugs.php.net/fix.php?id=79983&r=fixed
Fixed in release:                 https://bugs.php.net/fix.php?id=79983&r=alreadyfixed
Need backtrace:                   https://bugs.php.net/fix.php?id=79983&r=needtrace
Need Reproduce Script:            https://bugs.php.net/fix.php?id=79983&r=needscript
Try newer version:                https://bugs.php.net/fix.php?id=79983&r=oldversion
Not developer issue:              https://bugs.php.net/fix.php?id=79983&r=support
Expected behavior:                https://bugs.php.net/fix.php?id=79983&r=notwrong
Not enough info:                  https://bugs.php.net/fix.php?id=79983&r=notenoughinfo
Submitted twice:                  https://bugs.php.net/fix.php?id=79983&r=submittedtwice
register_globals:                 https://bugs.php.net/fix.php?id=79983&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=79983&r=phptooold
Daylight Savings:                 https://bugs.php.net/fix.php?id=79983&r=dst
IIS Stability:                    https://bugs.php.net/fix.php?id=79983&r=isapi
Install GNU Sed:                  https://bugs.php.net/fix.php?id=79983&r=gnused
Floating point limitations:       https://bugs.php.net/fix.php?id=79983&r=float
No Zend Extensions:               https://bugs.php.net/fix.php?id=79983&r=nozend
MySQL Configuration Error:        https://bugs.php.net/fix.php?id=79983&r=mysqlcfg


Thread (8 messages)

« previous php.bugs (#228618) next »