Bug #77156 [Opn->Csd]: Useless warning for AEAD
Edit report at https://bugs.php.net/bug.php?id=77156&edit=1
ID: 77156
Updated by: cmb@php.net
Reported by: obreham at gmail dot com
Summary: Useless warning for AEAD
-Status: Open
+Status: Closed
Type: Bug
Package: OpenSSL related
Operating System: Windows
PHP Version: 7.1.24
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This has been fixed in the meantime:
<https://github.com/php/php-src/commit/6c6a58e930c5863ab1bd11f6a19cbf22aa2f20d4>.
Previous Comments:
------------------------------------------------------------------------
[2018-11-14 22:56:30] obreham at gmail dot com
Description:
------------
PHP version: 7.1.9
The documentation for openssl_encrypt() indicates that the default &$tag = NULL, which should be
true for any case.
But if a $tag is deliberately passed - even when set to NULL - with a cipher that does not support
AEAD, a warning is triggered. This warning is not even mentioned in the documentation.
There are no needs for this warning, especially when it is the default value (NULL). The function
does set the $tag to NULL (no matter its initial value) and the correct encrypted data is returned.
Nothing unexpected happens.
As an aside, there is also a typo in the error message, it should read "does not" and not
"doesn not".
Test script:
---------------
$tag = null;
$encrypted = openssl_encrypt(
'data',
'aes-256-ctr',
'password',
0,
'1234567812345467',
$tag
);
var_dump($tag, $encrypted);
Expected result:
----------------
NULL
string(8) "/fQItQ=="
Actual result:
--------------
Warning: openssl_encrypt(): The authenticated tag cannot be provided for cipher that doesn not
support AEAD in C:\wamp\www\test\test.php on line 8
NULL
string(8) "/fQItQ=="
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77156&edit=1
Thread (2 messages)