Edit report at https://bugs.php.net/bug.php?id=80430&edit=1
ID: 80430
Updated by: bukka@php.net
Reported by: m dot saifmumtaz at gmail dot com
Summary: openssl_encrypt() is not verifying that key is
present or not.
Status: Open
-Type: Bug
+Type: Documentation Problem
Package: OpenSSL related
Operating System: Linux OpenSuse Tumbleweed
PHP Version: 7.4.13
Block user comment: N
Private report: N
New Comment:
This is actually more a documentation issue or requested as the 3rd argument is not a key but more a
passphrase (that's how it's now called in PHP 8 - before we called it password which is
how it's called in the code). The logic is basically that if it's shorter, then it's
padded with '\0' characters otherwise if longer it's trimmed. That's how it has
been always working and we can't really change it without breaking a code or having that as
optional thing.
Previous Comments:
------------------------------------------------------------------------
[2020-11-27 07:55:09] m dot saifmumtaz at gmail dot com
Description:
------------
openssl_encrypt() is not verifying the key lenght for given ciphering method. it encrpts and
decrypts even with empty key. it is not verifying the key in any mode even with aes-gcm have same
problem
Test script:
---------------
$key="";
$plaintext = "message to be encrypted";
$cipher = "aes-128-cbc";
if (in_array($cipher, openssl_get_cipher_methods()))
{
$ivlen = openssl_cipher_iv_length($cipher);
$iv = openssl_random_pseudo_bytes($ivlen);
$ciphertext = openssl_encrypt($plaintext, $cipher, $key, $options=0, $iv);
//store $cipher, $iv, and $tag for decryption later
$original_plaintext = openssl_decrypt($ciphertext, $cipher, $key, $options=0, $iv);
echo $original_plaintext."\n";
}
Expected result:
----------------
it must throw error if key length is not enough or empty.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80430&edit=1