Bug #79983 [Ver->Csd]: openssl_encrypt / openssl_decrypt fail with OCB mode
| From: | nikic@php.net | Date: | Mon, 19 Oct 2020 09:10:17 +0000 |
| Subject: | Bug #79983 [Ver->Csd]: openssl_encrypt / openssl_decrypt fail with OCB mode | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-229732@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79983&edit=1
ID: 79983
Updated by: nikic@php.net
Reported by: bizxing at web dot de
Summary: openssl_encrypt / openssl_decrypt fail with OCB mode
-Status: Verified
+Status: Closed
Type: Bug
Package: OpenSSL related
Operating System: Win 10
PHP Version: Irrelevant
Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=750a74ed9c8061681dba26ffc779c81b391b7718
Log: Fix bug #79983: Add support for OCB mode
Previous Comments:
------------------------------------------------------------------------
[2020-10-14 14:11:51] nikic@php.net
The following pull request has been associated:
Patch Name: Add support for OCB mode in OpenSSL
On GitHub: https://github.com/php/php-src/pull/6337
Patch: https://github.com/php/php-src/pull/6337.patch
------------------------------------------------------------------------
[2020-10-14 10:46:50] nikic@php.net
Ah, looks like OCB support was only added in OpenSSL 1.1, and now there are also generic controls
like EVP_CTRL_AEAD_SET_TAG, rather then cipher-specific ones.
https://www.openssl.org/docs/man1.1.0/man3/EVP_CIPHER_CTX_ctrl.html
------------------------------------------------------------------------
[2020-10-14 10:33:25] nikic@php.net
Related To: Bug #80232
------------------------------------------------------------------------
[2020-08-16 21:06:41] bizxing at web dot de
Description:
------------
Although the OCB mode (authenticated encryption) is included in the list of available algorithms
(e.g. [33] => aes-256-ocb) it is not properly supported. openssl_encrypt causes the error
message: >The authenticated tag cannot be provided for cipher that doesn not support AEAD<. No
tag is provided. However, the generated ciphertext seems to be correct. openssl_decrypt returns
false. If aes-256-ocb is replaced by e.g. aes-256-gcm, it works as expected.
Test script:
---------------
//echo print_r(openssl_get_cipher_methods(), true);
$plaintext = "The quick brown fox jumps over the lazy dog";
$cipher = 'aes-256-ocb';
$key = '01234567890123456789012345678901';
$iv = '012345678901';
$ciphertext = openssl_encrypt($plaintext, $cipher, $key, OPENSSL_RAW_DATA, $iv, $tag);
echo "tag (hex): " . bin2hex($tag) . PHP_EOL ;
echo "ciphertext (hex): " . bin2hex($ciphertext) . PHP_EOL ;
$recovered = openssl_decrypt($ciphertext, $cipher, $key, OPENSSL_RAW_DATA, $iv, $tag);
echo "recovered: " . ($recovered == false ? 'false' : $recovered) . PHP_EOL ;
Expected result:
----------------
For the OCB mode, analogous to the GCM/CCM mode, a tag should be generated during encryption (6th
parameter, $tag), which is used for authentication during decryption.
Actual result:
--------------
See description / test script
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79983&edit=1