Req #75804 [ReO->Csd]: authenticated encryption tag is broken
| From: | nikic@php.net | Date: | Wed, 30 Dec 2020 11:59:08 +0000 |
| Subject: | Req #75804 [ReO->Csd]: authenticated encryption tag is broken | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-231312@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75804&edit=1
ID: 75804
Updated by: nikic@php.net
Reported by: sergiuthepenguin at gmail dot com
Summary: authenticated encryption tag is broken
-Status: Re-Opened
+Status: Closed
Type: Feature/Change Request
Package: OpenSSL related
Operating System: Windows and GNU/Linux
PHP Version: 7.1.13
Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of mumumu
Revision: http://git.php.net/?p=doc/ja.git;a=commit;h=fdbe569241e6ce7930f7b2618f8448f4be2bdfa4
Log: Fix #75804: authenticated encryption tag is broken
Previous Comments:
------------------------------------------------------------------------
[2020-08-20 20:37:26] cmb@php.net
phpdocbot was not supposed to close this. :)
------------------------------------------------------------------------
[2020-08-20 17:20:07] phpdocbot@php.net
Automatic comment on behalf of mumumu
Revision: http://git.php.net/?p=doc/ja.git;a=commit;h=244520d6ee50dfe57266368e3b24adc75eedc474
Log: Fix #75804: authenticated encryption tag is broken
------------------------------------------------------------------------
[2020-08-20 10:34:54] cmb@php.net
This issue has now been documented[1]. Changing to feature
request.
[1] <<http://svn.php.net/viewvc?view=revision&revision=350346>>
------------------------------------------------------------------------
[2020-02-09 19:55:10] bukka@php.net
This is known thing and that's how OpenSSL works as well. I agree that we should document this.
Not sure about extra parameter as that's pretty easy to do in user land. Also we would need a
default value which would break the cases that use shorter tag. But I guess this could be acceptable
for 8.0. Might be a good idea though.
------------------------------------------------------------------------
[2018-01-26 17:21:27] sergiuthepenguin at gmail dot com
Thanks for confirming.
IMHO, the documentation should be updated to warn developers about manually verifying the tag length
using isset($tag[$chosenLength - 1]) or mb_strlen($tag, '8bit').
Speaking of which, is it not possible for openssl_decrypt to have a tag length argument for internal
checks?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=75804
--
Edit this bug report at https://bugs.php.net/bug.php?id=75804&edit=1