[php-src] Issue #7737: openssl_seal()/_open() is not able to handle gcm cipers, e.g. aes-256-gcm
| From: | bukka | Date: | Thu, 16 Dec 2021 22:10:08 +0000 |
| Subject: | [php-src] Issue #7737: openssl_seal()/_open() is not able to handle gcm cipers, e.g. aes-256-gcm | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-238456@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/7737
Comment Author: bukka
I don't think there's any issue in OpenSSL so you can probably close that linked ticket in
OpenSSL. This is just a missing functionality in PHP and it's really a feature request.
Basically
EVP_Seal* are just wrappers around EVP_Encrypt* that allows
encrypting the key with the supplied pkey. What PHP doesn't do is to provide a way to return a
tag. Although you could probably write your version of sealing in PHP to give you the same
functionality ( you might get an idea when you look to https://github.com/openssl/openssl/blob/defe51c178e3dc9f07514c179121021fd78691b4/crypto/evp/p_seal.c
). That said we could possibly add extra parameters to openssl_seal to return tag and
also extend openssl_open accordingly. So that's why this should be a feature
request.