note 40397 deleted from ref.mcrypt by danbrown
| From: | danbrown@php.net | Date: | Mon, 13 Dec 2010 16:27:55 +0000 |
| Subject: | note 40397 deleted from ref.mcrypt by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-174875@lists.php.net to get a copy of this message | ||
Note Submitter: robert at peakepro dot com
----
15-Feb-2004 06:17
"I found this nested loop very useful for checking the sanity of my libmcrypt install. It
turned out many of the modules weren't working in certain modes. Hopefully this will save
someone some frustration:"
I have ammended the mcrypt_check_sanity() function. This is a bug fix: the function was
reinitializing the IV, which is unacceptable. Here is the complete, fixed version. Note that
'stream' mode is not tested.
<?PHP
/* run a self-test through every listed cipher and mode */
function mcrypt_check_sanity() {
$modes = mcrypt_list_modes();
$algorithms = mcrypt_list_algorithms();
foreach ($algorithms as $cipher) {
if(mcrypt_module_self_test($cipher)) {
print $cipher." ok.<br />\n";
} else {
print $cipher." not ok.<br />\n";
}
foreach ($modes as $mode) {
if($mode == 'stream') {
$result = "not tested";
} else if(mcrypt_test_module_mode($cipher,$mode)) {
$result = "ok";
} else {
$result = "not ok";
}
print $cipher." in mode ".$mode." ".$result."<br />\n";
mcrypt_module_close($td);
}
}
}
// a variant on the example posted in mdecrypt_generic
function mcrypt_test_module_mode($module,$mode) {
/* Data */
$key = 'this is a very long key, even too long for the cipher';
$plain_text = 'very important data';
/* Open module, and create IV */
$td = mcrypt_module_open($module, '',$mode, '');
$key = substr($key, 0, mcrypt_enc_get_key_size($td));
$iv_size = mcrypt_enc_get_iv_size($td);
$iv = mcrypt_create_iv($iv_size, MCRYPT_RAND);
/* Initialize encryption handle */
if (mcrypt_generic_init($td, $key, $iv) != -1) {
/* Encrypt data */
$c_t = mcrypt_generic($td, $plain_text);
mcrypt_generic_deinit($td);
// close the module
mcrypt_module_close($td);
/* Reinitialize buffers for decryption */
/* Open module */
$td = mcrypt_module_open($module, '', $mode, '');
$key = substr($key, 0, mcrypt_enc_get_key_size($td));
mcrypt_generic_init($td, $key, $iv);
$p_t = trim(mdecrypt_generic($td, $c_t)); //trim to remove padding
/* Clean up */
mcrypt_generic_end($td);
mcrypt_module_close($td);
}
if (strncmp($p_t, $plain_text, strlen($plain_text)) == 0) {
return TRUE;
} else {
return FALSE;
}
}
// function call:
mcrypt_check_sanity();
?>
Apologies for any confusion the previous version may have caused. The only working mode listed was
ecb, since it does not use an IV.