Req #70439 [Asn->Csd]: Deprecate default method for openssl_seal and openssl_open
| From: | cmb@php.net | Date: | Thu, 05 Nov 2020 13:24:47 +0000 |
| Subject: | Req #70439 [Asn->Csd]: Deprecate default method for openssl_seal and openssl_open | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-230131@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70439&edit=1
ID: 70439
Updated by: cmb@php.net
Reported by: bukka@php.net
Summary: Deprecate default method for openssl_seal and
openssl_open
-Status: Assigned
+Status: Closed
Type: Feature/Change Request
Package: OpenSSL related
Operating System: any
PHP Version: Next Minor Version
Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
This has already been implemented[1], and will be available as of
PHP 8.0.0.
[1] <http://git.php.net/?p=php-src.git;a=commit;h=3e149427561dc04650aacfa61f9eb431da397997>
Previous Comments:
------------------------------------------------------------------------
[2015-09-06 17:27:58] bukka@php.net
Description:
------------
The default method for openssl_seal and openssl_open is RC4 which is a weak cipher. For that reason,
user should always choose a cipher algorithm (method parameter) explicitly.
The request is to deprecate calling openssl_seal and openssl_open without and method argument
(deprecate error message will be printed if the user doesn't supply a method parameter). The
method parameter will be then made required in the next major version.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70439&edit=1