Doc #51146 [Ana->Csd]: mcrypt doesn't do OFB mode correctly

From: Date: Tue, 08 May 2018 14:24:43 +0000
Subject: Doc #51146 [Ana->Csd]: mcrypt doesn't do OFB mode correctly
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-15658@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=51146&edit=1 ID: 51146 Updated by: cmb@php.net Reported by: zelnaga at gmail dot com Summary: mcrypt doesn't do OFB mode correctly -Status: Analyzed +Status: Closed Type: Documentation Problem Package: mcrypt related Operating System: Windows XP PHP Version: 5.3.1 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: This bug has been fixed in the documentation's XML sources. Since the online and downloadable versions of the documentation need some time to get updated, we would like to ask you to be a bit patient. Thank you for the report, and for helping us make our documentation better. Previous Comments: ------------------------------------------------------------------------ [2018-05-08 14:24:02] cmb@php.net Automatic comment from SVN on behalf of cmb Revision: http://svn.php.net/viewvc/?view=revision&revision=344989 Log: Some clarity on cipher modes for bug #51146 Patch provided by leigh. ------------------------------------------------------------------------ [2017-01-10 16:30:16] nikic@php.net Reclassifying as documentation problem for part 1). As the mcrypt extension has been killed, we won't be adding new constants -- the documentation should state that the string should be passed directly for this. ------------------------------------------------------------------------ [2017-01-10 14:28:26] leigh@php.net Ok, so what this boils down to is: 1) A documentation issue that mcrypt's implementation of OFB and CFB (as represented by MODE_OFB and MODE_CFB) operate in 8-bit mode, and that NCFB operates on full blocks. 2) A feature request to wrap mcrypt's MODE_NCFB constant. ------------------------------------------------------------------------ [2017-01-10 12:06:25] php at haravikk dot me I'm sorry but I believe this has been closed prematurely; as I have pointed out, mcrypt is in fact operating correctly, the issue here is that the behaviour of its CFB and OFB modes is misleading as it is per-byte, rather than per-state size block. The solution is to use the MCRYPT_MODE_NOFB constant, or to request ncfb mode via string, as the n signifies that these are scaled to the size of the state/key, so 128, 192 or 256 bits. As I stated in my earlier comment, the problem is in fact on the PHP side in so far as there is no MCRYPT_MODE_NCFB constant, and that the documentation for the CFB and OFB constants do not clarify that these are per-byte modes of operation. I believe that these are therefore issues with PHP's libmcrypt wrapper, not libmcrypt itself, and should be resolvable (especially after nearly seven years!) ------------------------------------------------------------------------ [2016-12-14 23:47:59] leigh@php.net Closing because it's not PHP implementing the encryption modes, it's libmcrypt which is unmaintained. The assumption that encrypting in OFB and decrypting in ECB should yield the IV at the start of the plaintext (where the original plaintext is entirely null bytes) is correct. If mcrypt does not do this, it is a problem with the third party library, the PHP module is just a wrapper. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=51146 -- Edit this bug report at https://bugs.php.net/bug.php?id=51146&edit=1

« previous php.doc.bugs (#15658) next »