Bug #81502 [Opn->Fbk]: Problem with $tag argument of openssl_decrypt()

From: Date: Tue, 05 Oct 2021 15:17:30 +0000
Subject: Bug #81502 [Opn->Fbk]: Problem with $tag argument of openssl_decrypt()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-237052@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81502&edit=1

 ID:                 81502
 Updated by:         nikic@php.net
 Reported by:        alec at alec dot pl
 Summary:            Problem with $tag argument of openssl_decrypt()
-Status:             Open
+Status:             Feedback
 Type:               Bug
 Package:            OpenSSL related
 PHP Version:        8.1.0RC3
 Block user comment: N
 Private report:     N

 New Comment:

I can't reproduce this. Empty tag for non-AEAD cipher does not produce a warning for me and
also matches my reading of the code (see https://github.com/php/php-src/blob/f313854c98e79fa5f4ec5ef9bf8755a15290b1a5/ext/openssl/openssl.c#L7333).

Can you please provide a complete reproducer that demonstrates the issue?


Previous Comments:
------------------------------------------------------------------------
[2021-10-04 17:12:50] alec at alec dot pl

Description:
------------
If I do:

$tag = null;
openssl_decrypt($cipher, $method, $ckey, $opts, $iv, $tag);

I get:

PHP Deprecated:  openssl_decrypt(): Passing null to parameter #6 ($tag) of type string is
deprecated.

But if I do:

$tag = '';
openssl_decrypt($cipher, $method, $ckey, $opts, $iv, $tag);

I get:

PHP Warning:  openssl_decrypt(): The tag cannot be used because the cipher algorithm does not
support AEAD.

I understand the warnings, but this is not convenient if my code is supposed to support AEAD and
non-AEAD cipher methods. Do I have to do two code paths depending on the cipher method is used?

What's more. The default value for the $tag argument in openssl_encrypt() is null, which sounds
kind of inconsistent.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=81502&edit=1


Thread (9 messages)

« previous php.bugs (#237052) next »