Doc #80430 [Ver->Csd]: openssl_encrypt() is not verifying that key is present or not.

From: Date: Mon, 28 Dec 2020 14:38:22 +0000
Subject: Doc #80430 [Ver->Csd]: openssl_encrypt() is not verifying that key is present or not.
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-18332@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80430&edit=1 ID: 80430 Updated by: phpdocbot@php.net Reported by: m dot saifmumtaz at gmail dot com Summary: openssl_encrypt() is not verifying that key is present or not. -Status: Verified +Status: Closed Type: Documentation Problem Package: OpenSSL related Operating System: Linux OpenSuse Tumbleweed PHP Version: 7.4.13 Assigned To: cmb Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmb Revision: http://git.php.net/?p=doc/en.git;a=commit;h=f467e8922859bc0760f1323575b6729fa3e1f4b2 Log: Fix #80430: openssl_encrypt() is not verifying that key is present or not Previous Comments: ------------------------------------------------------------------------ [2020-12-28 14:37:03] cmb@php.net Automatic comment from SVN on behalf of cmb Revision: http://svn.php.net/viewvc/?view=revision&revision=352242 Log: Fix #80430: openssl_encrypt() is not verifying that key is present or not ------------------------------------------------------------------------ [2020-12-27 18:16:44] bukka@php.net This is actually more a documentation issue or requested as the 3rd argument is not a key but more a passphrase (that's how it's now called in PHP 8 - before we called it password which is how it's called in the code). The logic is basically that if it's shorter, then it's padded with '\0' characters otherwise if longer it's trimmed. That's how it has been always working and we can't really change it without breaking a code or having that as optional thing. ------------------------------------------------------------------------ [2020-11-27 07:55:09] m dot saifmumtaz at gmail dot com Description: ------------ openssl_encrypt() is not verifying the key lenght for given ciphering method. it encrpts and decrypts even with empty key. it is not verifying the key in any mode even with aes-gcm have same problem Test script: --------------- $key=""; $plaintext = "message to be encrypted"; $cipher = "aes-128-cbc"; if (in_array($cipher, openssl_get_cipher_methods())) { $ivlen = openssl_cipher_iv_length($cipher); $iv = openssl_random_pseudo_bytes($ivlen); $ciphertext = openssl_encrypt($plaintext, $cipher, $key, $options=0, $iv); //store $cipher, $iv, and $tag for decryption later $original_plaintext = openssl_decrypt($ciphertext, $cipher, $key, $options=0, $iv); echo $original_plaintext."\n"; } Expected result: ---------------- it must throw error if key length is not enough or empty. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80430&edit=1

« previous php.doc.bugs (#18332) next »