Bug #79983 [Ver->Csd]: openssl_encrypt / openssl_decrypt fail with OCB mode

From: Date: Mon, 19 Oct 2020 09:10:17 +0000
Subject: Bug #79983 [Ver->Csd]: openssl_encrypt / openssl_decrypt fail with OCB mode
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229732@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79983&edit=1 ID: 79983 Updated by: nikic@php.net Reported by: bizxing at web dot de Summary: openssl_encrypt / openssl_decrypt fail with OCB mode -Status: Verified +Status: Closed Type: Bug Package: OpenSSL related Operating System: Win 10 PHP Version: Irrelevant Assigned To: nikic Block user comment: N Private report: N New Comment: Automatic comment on behalf of nikita.ppv@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=750a74ed9c8061681dba26ffc779c81b391b7718 Log: Fix bug #79983: Add support for OCB mode Previous Comments: ------------------------------------------------------------------------ [2020-10-14 14:11:51] nikic@php.net The following pull request has been associated: Patch Name: Add support for OCB mode in OpenSSL On GitHub: https://github.com/php/php-src/pull/6337 Patch: https://github.com/php/php-src/pull/6337.patch ------------------------------------------------------------------------ [2020-10-14 10:46:50] nikic@php.net Ah, looks like OCB support was only added in OpenSSL 1.1, and now there are also generic controls like EVP_CTRL_AEAD_SET_TAG, rather then cipher-specific ones. https://www.openssl.org/docs/man1.1.0/man3/EVP_CIPHER_CTX_ctrl.html ------------------------------------------------------------------------ [2020-10-14 10:33:25] nikic@php.net Related To: Bug #80232 ------------------------------------------------------------------------ [2020-08-16 21:06:41] bizxing at web dot de Description: ------------ Although the OCB mode (authenticated encryption) is included in the list of available algorithms (e.g. [33] => aes-256-ocb) it is not properly supported. openssl_encrypt causes the error message: >The authenticated tag cannot be provided for cipher that doesn not support AEAD<. No tag is provided. However, the generated ciphertext seems to be correct. openssl_decrypt returns false. If aes-256-ocb is replaced by e.g. aes-256-gcm, it works as expected. Test script: --------------- //echo print_r(openssl_get_cipher_methods(), true); $plaintext = "The quick brown fox jumps over the lazy dog"; $cipher = 'aes-256-ocb'; $key = '01234567890123456789012345678901'; $iv = '012345678901'; $ciphertext = openssl_encrypt($plaintext, $cipher, $key, OPENSSL_RAW_DATA, $iv, $tag); echo "tag (hex): " . bin2hex($tag) . PHP_EOL ; echo "ciphertext (hex): " . bin2hex($ciphertext) . PHP_EOL ; $recovered = openssl_decrypt($ciphertext, $cipher, $key, OPENSSL_RAW_DATA, $iv, $tag); echo "recovered: " . ($recovered == false ? 'false' : $recovered) . PHP_EOL ; Expected result: ---------------- For the OCB mode, analogous to the GCM/CCM mode, a tag should be generated during encryption (6th parameter, $tag), which is used for authentication during decryption. Actual result: -------------- See description / test script ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=79983&edit=1

« previous php.bugs (#229732) next »