Edit report at https://bugs.php.net/bug.php?id=81502&edit=1
ID: 81502
Updated by: git@php.net
Reported by: alec at alec dot pl
Summary: $tag argument of openssl_decrypt() should accept
null/empty string
-Status: Open
+Status: Closed
Type: Bug
Package: OpenSSL related
PHP Version: 8.1.0RC3
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikic
Revision: https://github.com/php/php-src/commit/7f0d3f5413dfbd989ffe34a417c61210441763f3
Log: Fixed bug #81502
Previous Comments:
------------------------------------------------------------------------
[2021-10-08 07:49:47] nikic@php.net
But anyway, I do agree that we should accept null $tag here. I believe openssl_encrypt() will set it
to null for non-aead ciphers, so it only makes sense to also accept this as an input.
------------------------------------------------------------------------
[2021-10-08 07:44:03] nikic@php.net
I still can't reproduce this: If I change your code to use "$tag = '';"
instead of "$tag = null;" then I don't get a warning on PHP 8.1. I also checked older
versions in case that's recent behavior, but those also don't throw a warning for an empty
tag string.
------------------------------------------------------------------------
[2021-10-08 05:28:34] alec at alec dot pl
Summary updated
------------------------------------------------------------------------
[2021-10-07 06:29:57] alec at alec dot pl
Again, to make it clear. I want openssl_decrypt() to support null or empty string in $tag argument
(as not existing) for non-AEAD ciphers.
My real code is here: https://github.com/roundcube/roundcubemail/blob/318d6d08597bbfe481e01bf989150faa8c0403e5/program/lib/Roundcube/rcube.php#L894
With php8.0 I can have ($tag is null):
openssl_decrypt($cipher, $method, $ckey, OPENSSL_RAW_DATA, $iv, $tag);
with php8.1 it throws a deprecation warning, I cannot use this:
openssl_decrypt($cipher, $method, $ckey, OPENSSL_RAW_DATA, $iv, (string) $tag);
because it throws the other warning. I have to use:
if ($tag === null) {
openssl_decrypt($cipher, $method, $ckey, OPENSSL_RAW_DATA, $iv);
} else {
openssl_decrypt($cipher, $method, $ckey, OPENSSL_RAW_DATA, $iv, $tag);
}
which I don't like.
------------------------------------------------------------------------
[2021-10-05 17:08:21] alec at alec dot pl
```
<?php
ini_set('error_reporting', E_ALL);
ini_set('display_errors', 'on');
function encrypt($clear)
{
$key = 'key';
$ckey = '123456789012345678901234';
$method = 'DES-EDE3-CBC';
$opts = OPENSSL_RAW_DATA;
$iv = random_bytes(openssl_cipher_iv_length($method));
$cipher = openssl_encrypt($clear, $method, $ckey, $opts, $iv, $tag);
$cipher = $iv . $cipher;
return $cipher;
}
function decrypt($cipher)
{
$key = 'key';
$ckey = '123456789012345678901234';
$method = 'DES-EDE3-CBC';
$opts = OPENSSL_RAW_DATA;
$iv_size = openssl_cipher_iv_length($method);
$tag = null;
$iv = substr($cipher, 0, $iv_size);
$cipher = substr($cipher, $iv_size);
return openssl_decrypt($cipher, $method, $ckey, $opts, $iv, $tag);
}
echo decrypt(encrypt('test')) === 'test';
```
One correction, I'm using PHP 8.1.0RC2 on Ubuntu 18.04.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=81502
--
Edit this bug report at https://bugs.php.net/bug.php?id=81502&edit=1