Doc #80430 [Opn->Ver]: openssl_encrypt() is not verifying that key is present or not.

From: Date: Mon, 28 Dec 2020 14:35:19 +0000
Subject: Doc #80430 [Opn->Ver]: openssl_encrypt() is not verifying that key is present or not.
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-18331@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80430&edit=1

 ID:                 80430
 Updated by:         cmb@php.net
 Reported by:        m dot saifmumtaz at gmail dot com
 Summary:            openssl_encrypt() is not verifying that key is
                     present or not.
-Status:             Open
+Status:             Verified
 Type:               Documentation Problem
 Package:            OpenSSL related
 Operating System:   Linux OpenSuse Tumbleweed
 PHP Version:        7.4.13
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N



Previous Comments:
------------------------------------------------------------------------
[2020-12-27 18:16:44] bukka@php.net

This is actually more a documentation issue or requested as the 3rd argument is not a key but more a
passphrase (that's how it's now called in PHP 8 - before we called it password which is
how it's called in the code). The logic is basically that if it's shorter, then it's
padded with '\0' characters otherwise if longer it's trimmed. That's how it has
been always working and we can't really change it without breaking a code or having that as
optional thing.

------------------------------------------------------------------------
[2020-11-27 07:55:09] m dot saifmumtaz at gmail dot com

Description:
------------
openssl_encrypt() is not verifying the key lenght for given ciphering method. it encrpts and
decrypts even with empty key. it is not verifying the key in any mode even with aes-gcm have same
problem

Test script:
---------------
$key="";
$plaintext = "message to be encrypted";
$cipher = "aes-128-cbc";
if (in_array($cipher, openssl_get_cipher_methods()))
{
    $ivlen = openssl_cipher_iv_length($cipher);
    $iv = openssl_random_pseudo_bytes($ivlen);
    $ciphertext = openssl_encrypt($plaintext, $cipher, $key, $options=0, $iv);
    //store $cipher, $iv, and $tag for decryption later
    $original_plaintext = openssl_decrypt($ciphertext, $cipher, $key, $options=0, $iv);
    echo $original_plaintext."\n";
}

Expected result:
----------------
it must throw error if key length is not enough or empty.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=80430&edit=1


Thread (3 messages)

« previous php.doc.bugs (#18331) next »