Req #75804 [ReO->Csd]: authenticated encryption tag is broken

From: Date: Wed, 30 Dec 2020 11:59:08 +0000
Subject: Req #75804 [ReO->Csd]: authenticated encryption tag is broken
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-231312@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75804&edit=1 ID: 75804 Updated by: nikic@php.net Reported by: sergiuthepenguin at gmail dot com Summary: authenticated encryption tag is broken -Status: Re-Opened +Status: Closed Type: Feature/Change Request Package: OpenSSL related Operating System: Windows and GNU/Linux PHP Version: 7.1.13 Assigned To: bukka Block user comment: N Private report: N New Comment: Automatic comment on behalf of mumumu Revision: http://git.php.net/?p=doc/ja.git;a=commit;h=fdbe569241e6ce7930f7b2618f8448f4be2bdfa4 Log: Fix #75804: authenticated encryption tag is broken Previous Comments: ------------------------------------------------------------------------ [2020-08-20 20:37:26] cmb@php.net phpdocbot was not supposed to close this. :) ------------------------------------------------------------------------ [2020-08-20 17:20:07] phpdocbot@php.net Automatic comment on behalf of mumumu Revision: http://git.php.net/?p=doc/ja.git;a=commit;h=244520d6ee50dfe57266368e3b24adc75eedc474 Log: Fix #75804: authenticated encryption tag is broken ------------------------------------------------------------------------ [2020-08-20 10:34:54] cmb@php.net This issue has now been documented[1]. Changing to feature request. [1] <<http://svn.php.net/viewvc?view=revision&revision=350346>> ------------------------------------------------------------------------ [2020-02-09 19:55:10] bukka@php.net This is known thing and that's how OpenSSL works as well. I agree that we should document this. Not sure about extra parameter as that's pretty easy to do in user land. Also we would need a default value which would break the cases that use shorter tag. But I guess this could be acceptable for 8.0. Might be a good idea though. ------------------------------------------------------------------------ [2018-01-26 17:21:27] sergiuthepenguin at gmail dot com Thanks for confirming. IMHO, the documentation should be updated to warn developers about manually verifying the tag length using isset($tag[$chosenLength - 1]) or mb_strlen($tag, '8bit'). Speaking of which, is it not possible for openssl_decrypt to have a tag length argument for internal checks? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=75804 -- Edit this bug report at https://bugs.php.net/bug.php?id=75804&edit=1

« previous php.bugs (#231312) next »