Req #81724 [Com]: openssl_cms/pkcs7_encrypt only allows specific ciphers

From: Date: Wed, 14 Dec 2022 05:22:12 +0000
Subject: Req #81724 [Com]: openssl_cms/pkcs7_encrypt only allows specific ciphers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-243139@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81724&edit=1 ID: 81724 Comment by: rorygwgehman at gmail dot com Reported by: johannes dot drummer at power dot cloud Summary: openssl_cms/pkcs7_encrypt only allows specific ciphers Status: Assigned Type: Feature/Change Request Package: OpenSSL related Operating System: Any PHP Version: 8.1.7 Assigned To: bukka Block user comment: N Private report: N New Comment: Thanks for this... https://www.gtaportal.org/github.com Previous Comments: ------------------------------------------------------------------------ [2022-12-14 03:46:48] rorygwgehman at gmail dot com Thanks https://www.tigerishome.org/github.com ------------------------------------------------------------------------ [2022-12-13 05:08:47] samira dot akhlaqi314 at gmail dot com A really good post, very thankful and hopeful that you will write many more posts like this one. (https://www.marykayintouch.ltd/)php.net ------------------------------------------------------------------------ [2022-07-06 07:41:34] johannes dot drummer at power dot cloud I originally created this request only for cms and not pkcs7 and I didn't check it, I just saw that it was using the same logic, sorry. ------------------------------------------------------------------------ [2022-07-05 22:57:24] bukka@php.net You are confusing normal encryption with PKCS7 and CMS enveloped encryption which has got its own RFC's and limited set of ciphers supported. For PKCS7 there will never be support for AEAD. In terms of CMS, there're RFC's for AEAD and I actually added support for AEAD AES-GCM to OpenSSL in https://github.com/openssl/openssl/pull/8024 which is in OpenSSL 3.0. I'm actually looking and I was wrong in assuming that we don't need any changes in openssl ext for that, which we actually do. So changing this to request to add that. ------------------------------------------------------------------------ [2022-07-05 15:25:26] johannes dot drummer at power dot cloud Description: ------------ php 8+ with openssl The openssl_cms_encrypt and openssl_pkcs7_encrypt function only allows an int as parameter for ciphers, referring to the enum php_openssl_cipher_type, that only contains ciphers, that are usually not recommended. Better options would be using AES_GCM,ChaCha20_Poly1305,AES_CTR... With openssl_encrypt we can use any cipher, because it resolves the string. My suggestion would be to change the API to accept strings and deprecate the enum version, or else it would be necessary to map all new cipher methods in the future. https://github.com/php/php-src/blob/f0c679c72ce02c1578ba9d56a099343b1eb3e16c/ext/openssl/openssl.c#L113-L124 https://github.com/php/php-src/blob/f0c679c72ce02c1578ba9d56a099343b1eb3e16c/ext/openssl/openssl.c#L6094-L6099 Test script: --------------- openssl_cms_encrypt( input_filename: $tempfileSigned, output_filename: $tempfileEncrypted, certificate: $recipientsCertificate, headers: [], flags: OPENSSL_CMS_BINARY | OPENSSL_CMS_NOSIGS | OPENSSL_CMS_NOVERIFY, encoding: OPENSSL_ENCODING_DER, cipher_algo: "aes-256-gcm" ); Expected result: ---------------- That the openssl function is executed and the cipher algo is resolved from the string. Actual result: -------------- It doesn't work with strings only a very short list of mapped ENUM. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81724&edit=1

« previous php.bugs (#243139) next »