Req #70439 [Asn->Csd]: Deprecate default method for openssl_seal and openssl_open

From: Date: Thu, 05 Nov 2020 13:24:47 +0000
Subject: Req #70439 [Asn->Csd]: Deprecate default method for openssl_seal and openssl_open
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-230131@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70439&edit=1 ID: 70439 Updated by: cmb@php.net Reported by: bukka@php.net Summary: Deprecate default method for openssl_seal and openssl_open -Status: Assigned +Status: Closed Type: Feature/Change Request Package: OpenSSL related Operating System: any PHP Version: Next Minor Version Assigned To: bukka Block user comment: N Private report: N New Comment: This has already been implemented[1], and will be available as of PHP 8.0.0. [1] <http://git.php.net/?p=php-src.git;a=commit;h=3e149427561dc04650aacfa61f9eb431da397997> Previous Comments: ------------------------------------------------------------------------ [2015-09-06 17:27:58] bukka@php.net Description: ------------ The default method for openssl_seal and openssl_open is RC4 which is a weak cipher. For that reason, user should always choose a cipher algorithm (method parameter) explicitly. The request is to deprecate calling openssl_seal and openssl_open without and method argument (deprecate error message will be printed if the user doesn't supply a method parameter). The method parameter will be then made required in the next major version. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70439&edit=1

« previous php.bugs (#230131) next »