Doc #51146 [Asn->Ana]: mcrypt doesn't do OFB mode correctly
| From: | kalle@php.net | Date: | Tue, 24 Oct 2017 06:46:48 +0000 |
| Subject: | Doc #51146 [Asn->Ana]: mcrypt doesn't do OFB mode correctly | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-15144@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=51146&edit=1
ID: 51146
Updated by: kalle@php.net
Reported by: zelnaga at gmail dot com
Summary: mcrypt doesn't do OFB mode correctly
-Status: Assigned
+Status: Analyzed
Type: Documentation Problem
Package: mcrypt related
Operating System: Windows XP
PHP Version: 5.3.1
-Assigned To: leigh
+Assigned To:
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2017-01-10 16:30:16] nikic@php.net
Reclassifying as documentation problem for part 1). As the mcrypt extension has been killed, we
won't be adding new constants -- the documentation should state that the string should be
passed directly for this.
------------------------------------------------------------------------
[2017-01-10 14:28:26] leigh@php.net
Ok, so what this boils down to is:
1) A documentation issue that mcrypt's implementation of OFB and CFB (as represented by
MODE_OFB and MODE_CFB) operate in 8-bit mode, and that NCFB operates on full blocks.
2) A feature request to wrap mcrypt's MODE_NCFB constant.
------------------------------------------------------------------------
[2017-01-10 12:06:25] php at haravikk dot me
I'm sorry but I believe this has been closed prematurely; as I have pointed out, mcrypt is in
fact operating correctly, the issue here is that the behaviour of its CFB and OFB modes is
misleading as it is per-byte, rather than per-state size block.
The solution is to use the MCRYPT_MODE_NOFB constant, or to request ncfb mode via string, as the n
signifies that these are scaled to the size of the state/key, so 128, 192 or 256 bits.
As I stated in my earlier comment, the problem is in fact on the PHP side in so far as there is no
MCRYPT_MODE_NCFB constant, and that the documentation for the CFB and OFB constants do not clarify
that these are per-byte modes of operation. I believe that these are therefore issues with
PHP's libmcrypt wrapper, not libmcrypt itself, and should be resolvable (especially after
nearly seven years!)
------------------------------------------------------------------------
[2016-12-14 23:47:59] leigh@php.net
Closing because it's not PHP implementing the encryption modes, it's libmcrypt which is
unmaintained.
The assumption that encrypting in OFB and decrypting in ECB should yield the IV at the start of the
plaintext (where the original plaintext is entirely null bytes) is correct. If mcrypt does not do
this, it is a problem with the third party library, the PHP module is just a wrapper.
------------------------------------------------------------------------
[2013-11-25 19:38:06] ywarnier at beeznest dot org
Sorry, I forgot to mention (if that has any incidence on this report) I use PHP 5.5.3 (mod_php5)
with the mcrypt module for 5.4.6.
How is that even possible, I don't know, but that's what my dear Ubuntu is telling me...
moving back to Debian soon, I swear :-p
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=51146
--
Edit this bug report at https://bugs.php.net/bug.php?id=51146&edit=1