Bug #79983 [Csd]: openssl_encrypt / openssl_decrypt fail with OCB mode
| From: | nikic@php.net | Date: | Thu, 03 Dec 2020 09:13:18 +0000 |
| Subject: | Bug #79983 [Csd]: openssl_encrypt / openssl_decrypt fail with OCB mode | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-230816@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79983&edit=1
ID: 79983
Updated by: nikic@php.net
Reported by: bizxing at web dot de
Summary: openssl_encrypt / openssl_decrypt fail with OCB mode
Status: Closed
Type: Bug
Package: OpenSSL related
Operating System: Win 10
PHP Version: Irrelevant
Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
@brad at pocketinnovations dot com dot au: This issue should already be fixed in HEAD.
Previous Comments:
------------------------------------------------------------------------
[2020-12-03 08:17:04] alex at ozo dot com
well, this is NOT an actual fix (from php part) but rather a workaround. the point is, that libressl
is NOT fully compatible (at least on this issue) with openssl as far as features support.
I (among others) are on the libressl land, but for this to remain, libressl needs to remain a good
alternative to openssl
my very humble 0,00002 cents
regards & many thanks
------------------------------------------------------------------------
[2020-12-03 00:30:24] brad at pocketinnovations dot com dot au
This patch breaks libressl compilation because OCB is not supported by libressl at this time. One
fix is to check that EVP_CIPH_OCB_MODE is also defined when checking openssl version
line 6496 of ext/openssl/openssl.c
int cipher_mode = EVP_CIPHER_mode(cipher_type);
memset(mode, 0, sizeof(struct php_openssl_cipher_mode));
switch (cipher_mode) {
-#if PHP_OPENSSL_API_VERSION >= 0x10100
+#if PHP_OPENSSL_API_VERSION >= 0x10100 && defined(EVP_CIPH_OCB_MODE)
case EVP_CIPH_GCM_MODE:
case EVP_CIPH_OCB_MODE:
case EVP_CIPH_CCM_MODE:
------------------------------------------------------------------------
[2020-10-19 09:10:17] nikic@php.net
Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=750a74ed9c8061681dba26ffc779c81b391b7718
Log: Fix bug #79983: Add support for OCB mode
------------------------------------------------------------------------
[2020-10-14 14:11:51] nikic@php.net
The following pull request has been associated:
Patch Name: Add support for OCB mode in OpenSSL
On GitHub: https://github.com/php/php-src/pull/6337
Patch: https://github.com/php/php-src/pull/6337.patch
------------------------------------------------------------------------
[2020-10-14 10:46:50] nikic@php.net
Ah, looks like OCB support was only added in OpenSSL 1.1, and now there are also generic controls
like EVP_CTRL_AEAD_SET_TAG, rather then cipher-specific ones.
https://www.openssl.org/docs/man1.1.0/man3/EVP_CIPHER_CTX_ctrl.html
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=79983
--
Edit this bug report at https://bugs.php.net/bug.php?id=79983&edit=1