Re: Re: OpenSSL ext. improvements for authenticated cipher modes.
| From: | Jakub Zelenka | Date: | Sun, 01 Feb 2015 18:07:06 +0000 |
| Subject: | Re: Re: OpenSSL ext. improvements for authenticated cipher modes. | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-81537@lists.php.net to get a copy of this message | ||
Hey,
On Sun, Feb 1, 2015 at 5:49 PM, Daniel Lowrey <rdlowrey@php.net> wrote:
>
> - openssl_decrypt() now returns mixed ... if $options['get_tag'] == true
> then return [$decryptedString, $tag], otherwise return $decrypted string as
> before to preserve BC.
> - the encrypt function could use $options['set_tag'] to define that (or
> any other secondary information needed for the operation).
>
I think that you confused it a bit :). The encryption results in cipher
text and a tag. The decryption then validates the tag so you pass the tag
as a parameter.
Except that it's almost the same what I thought. I'm just not sure that
mixed return value is a good idea. It seems a bit better having tag as a
reference to me. But it's just a small detail that could be added to the
RFC as a choice :)
Cheers
Jakub