Doc #80430 [Ver->Csd]: openssl_encrypt() is not verifying that key is present or not.
| From: | phpdocbot@php.net | Date: | Mon, 28 Dec 2020 14:38:22 +0000 |
| Subject: | Doc #80430 [Ver->Csd]: openssl_encrypt() is not verifying that key is present or not. | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-18332@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80430&edit=1
ID: 80430
Updated by: phpdocbot@php.net
Reported by: m dot saifmumtaz at gmail dot com
Summary: openssl_encrypt() is not verifying that key is
present or not.
-Status: Verified
+Status: Closed
Type: Documentation Problem
Package: OpenSSL related
Operating System: Linux OpenSuse Tumbleweed
PHP Version: 7.4.13
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmb
Revision: http://git.php.net/?p=doc/en.git;a=commit;h=f467e8922859bc0760f1323575b6729fa3e1f4b2
Log: Fix #80430: openssl_encrypt() is not verifying that key is present or not
Previous Comments:
------------------------------------------------------------------------
[2020-12-28 14:37:03] cmb@php.net
Automatic comment from SVN on behalf of cmb
Revision: http://svn.php.net/viewvc/?view=revision&revision=352242
Log: Fix #80430: openssl_encrypt() is not verifying that key is present or not
------------------------------------------------------------------------
[2020-12-27 18:16:44] bukka@php.net
This is actually more a documentation issue or requested as the 3rd argument is not a key but more a
passphrase (that's how it's now called in PHP 8 - before we called it password which is
how it's called in the code). The logic is basically that if it's shorter, then it's
padded with '\0' characters otherwise if longer it's trimmed. That's how it has
been always working and we can't really change it without breaking a code or having that as
optional thing.
------------------------------------------------------------------------
[2020-11-27 07:55:09] m dot saifmumtaz at gmail dot com
Description:
------------
openssl_encrypt() is not verifying the key lenght for given ciphering method. it encrpts and
decrypts even with empty key. it is not verifying the key in any mode even with aes-gcm have same
problem
Test script:
---------------
$key="";
$plaintext = "message to be encrypted";
$cipher = "aes-128-cbc";
if (in_array($cipher, openssl_get_cipher_methods()))
{
$ivlen = openssl_cipher_iv_length($cipher);
$iv = openssl_random_pseudo_bytes($ivlen);
$ciphertext = openssl_encrypt($plaintext, $cipher, $key, $options=0, $iv);
//store $cipher, $iv, and $tag for decryption later
$original_plaintext = openssl_decrypt($ciphertext, $cipher, $key, $options=0, $iv);
echo $original_plaintext."\n";
}
Expected result:
----------------
it must throw error if key length is not enough or empty.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80430&edit=1