Bug #80232 [Com]: openssl_decrypt() error with aes-128-ocb fail to set openssl_error_string()

From: Date: Wed, 14 Oct 2020 01:41:54 +0000
Subject: Bug #80232 [Com]: openssl_decrypt() error with aes-128-ocb fail to set openssl_error_string()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229603@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80232&edit=1

 ID:                 80232
 Comment by:         divinity76 at gmail dot com
 Reported by:        divinity76 at gmail dot com
 Summary:            openssl_decrypt() error with aes-128-ocb fail to set
                     openssl_error_string()
 Status:             Open
 Type:               Bug
 Package:            OpenSSL related
 PHP Version:        7.2.34
 Block user comment: N
 Private report:     N

 New Comment:

(i don't know if the return from openssl_encrypt() is valid or bogus, but the return string
looks like ciphertext to me, and _encrypt() doesn't set openssl_error_string() either)


Previous Comments:
------------------------------------------------------------------------
[2020-10-14 01:27:18] divinity76 at gmail dot com

Description:
------------
it seems some openssl_decrypt() decryption error with aes-128-ocb fail to register on
openssl_error_string()

Test script:
---------------
<?php
declare(strict_types=1);
ini_set('display_errors','On');
error_reporting(E_ALL);
header("Content-Type: text/plain;charset=utf-8");
ini_set('html_errors','0');
$algo = 'aes-128-ocb';
$data_to_encrypt = $key = $iv = str_repeat("\x00", openssl_cipher_iv_length($algo));
$opts = OPENSSL_RAW_DATA | OPENSSL_ZERO_PADDING;
$encrypted = openssl_encrypt($data_to_encrypt, $algo, $key, $opts , $iv);
if(false===$encrypted || openssl_error_string() !== false){
    die("encryption error ".openssl_error_string());
}
$decrypted = openssl_decrypt($encrypted, $algo, $key, $opts, $iv);
if(($encrypted !== $data_to_encrypt) && ($data_to_encrypt === $decrypted)){
    echo "ok";
}else{
    echo "error: ";
    var_dump([
        "original"=>$data_to_encrypt,
        "encrypted"=>$encrypted,
        "decrypted"=>$decrypted,
        "openssl_error_string" => openssl_error_string()
    ]);
}


Expected result:
----------------
i either expected "ok", or expected openssl_error_string() to contain something other than
bool(false) 

Actual result:
--------------
error: array(4) {
  ["original"]=>
  string(12) "������������"
  ["encrypted"]=>
  string(12) "{��f�g]�WG�"
  ["decrypted"]=>
  bool(false)
  ["openssl_error_string"]=>
  bool(false)
}


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=80232&edit=1


Thread (4 messages)

« previous php.bugs (#229603) next »