Bug #79983 [Csd]: openssl_encrypt / openssl_decrypt fail with OCB mode

From: Date: Thu, 03 Dec 2020 09:13:18 +0000
Subject: Bug #79983 [Csd]: openssl_encrypt / openssl_decrypt fail with OCB mode
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-230816@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79983&edit=1 ID: 79983 Updated by: nikic@php.net Reported by: bizxing at web dot de Summary: openssl_encrypt / openssl_decrypt fail with OCB mode Status: Closed Type: Bug Package: OpenSSL related Operating System: Win 10 PHP Version: Irrelevant Assigned To: nikic Block user comment: N Private report: N New Comment: @brad at pocketinnovations dot com dot au: This issue should already be fixed in HEAD. Previous Comments: ------------------------------------------------------------------------ [2020-12-03 08:17:04] alex at ozo dot com well, this is NOT an actual fix (from php part) but rather a workaround. the point is, that libressl is NOT fully compatible (at least on this issue) with openssl as far as features support. I (among others) are on the libressl land, but for this to remain, libressl needs to remain a good alternative to openssl my very humble 0,00002 cents regards & many thanks ------------------------------------------------------------------------ [2020-12-03 00:30:24] brad at pocketinnovations dot com dot au This patch breaks libressl compilation because OCB is not supported by libressl at this time. One fix is to check that EVP_CIPH_OCB_MODE is also defined when checking openssl version line 6496 of ext/openssl/openssl.c int cipher_mode = EVP_CIPHER_mode(cipher_type); memset(mode, 0, sizeof(struct php_openssl_cipher_mode)); switch (cipher_mode) { -#if PHP_OPENSSL_API_VERSION >= 0x10100 +#if PHP_OPENSSL_API_VERSION >= 0x10100 && defined(EVP_CIPH_OCB_MODE) case EVP_CIPH_GCM_MODE: case EVP_CIPH_OCB_MODE: case EVP_CIPH_CCM_MODE: ------------------------------------------------------------------------ [2020-10-19 09:10:17] nikic@php.net Automatic comment on behalf of nikita.ppv@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=750a74ed9c8061681dba26ffc779c81b391b7718 Log: Fix bug #79983: Add support for OCB mode ------------------------------------------------------------------------ [2020-10-14 14:11:51] nikic@php.net The following pull request has been associated: Patch Name: Add support for OCB mode in OpenSSL On GitHub: https://github.com/php/php-src/pull/6337 Patch: https://github.com/php/php-src/pull/6337.patch ------------------------------------------------------------------------ [2020-10-14 10:46:50] nikic@php.net Ah, looks like OCB support was only added in OpenSSL 1.1, and now there are also generic controls like EVP_CTRL_AEAD_SET_TAG, rather then cipher-specific ones. https://www.openssl.org/docs/man1.1.0/man3/EVP_CIPHER_CTX_ctrl.html ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=79983 -- Edit this bug report at https://bugs.php.net/bug.php?id=79983&edit=1

« previous php.bugs (#230816) next »