Bug #80232 [Opn->Dup]: openssl_decrypt() error with aes-128-ocb fail to set openssl_error_string()
Edit report at https://bugs.php.net/bug.php?id=80232&edit=1
ID: 80232
Updated by: nikic@php.net
Reported by: divinity76 at gmail dot com
Summary: openssl_decrypt() error with aes-128-ocb fail to set
openssl_error_string()
-Status: Open
+Status: Duplicate
Type: Bug
Package: OpenSSL related
PHP Version: 7.2.34
Block user comment: N
Private report: N
New Comment:
It's normal that openssl_decrypt() does not provide detailed error information -- providing
error information for decryption operations may break the security of the cipher.
However, something is clearly wrong with the handling of OCB here. It's an AEAD mode, but it
doesn't accept a tag, and thus decryption will also fail. Apparently this has been previously
reported in bug #79983.
Previous Comments:
------------------------------------------------------------------------
[2020-10-14 01:41:54] divinity76 at gmail dot com
(i don't know if the return from openssl_encrypt() is valid or bogus, but the return string
looks like ciphertext to me, and _encrypt() doesn't set openssl_error_string() either)
------------------------------------------------------------------------
[2020-10-14 01:27:18] divinity76 at gmail dot com
Description:
------------
it seems some openssl_decrypt() decryption error with aes-128-ocb fail to register on
openssl_error_string()
Test script:
---------------
<?php
declare(strict_types=1);
ini_set('display_errors','On');
error_reporting(E_ALL);
header("Content-Type: text/plain;charset=utf-8");
ini_set('html_errors','0');
$algo = 'aes-128-ocb';
$data_to_encrypt = $key = $iv = str_repeat("\x00", openssl_cipher_iv_length($algo));
$opts = OPENSSL_RAW_DATA | OPENSSL_ZERO_PADDING;
$encrypted = openssl_encrypt($data_to_encrypt, $algo, $key, $opts , $iv);
if(false===$encrypted || openssl_error_string() !== false){
die("encryption error ".openssl_error_string());
}
$decrypted = openssl_decrypt($encrypted, $algo, $key, $opts, $iv);
if(($encrypted !== $data_to_encrypt) && ($data_to_encrypt === $decrypted)){
echo "ok";
}else{
echo "error: ";
var_dump([
"original"=>$data_to_encrypt,
"encrypted"=>$encrypted,
"decrypted"=>$decrypted,
"openssl_error_string" => openssl_error_string()
]);
}
Expected result:
----------------
i either expected "ok", or expected openssl_error_string() to contain something other than
bool(false)
Actual result:
--------------
error: array(4) {
["original"]=>
string(12) "������������"
["encrypted"]=>
string(12) "{��f�g]�WG�"
["decrypted"]=>
bool(false)
["openssl_error_string"]=>
bool(false)
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80232&edit=1
Thread (4 messages)