note 40397 added to ref.mcrypt
| From: | robert at peakepro dot com | Date: | Tue, 02 Mar 2004 19:59:38 +0000 |
| Subject: | note 40397 added to ref.mcrypt | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-66127@lists.php.net to get a copy of this message | ||
I have ammended the mcrypt_check_sanity() function. This is a bug fix: the function was
reinitializing the IV, which is unacceptable. Here is the complete, fixed version. Note that
'stream' mode is not tested.
<?PHP
/* run a self-test through every listed cipher and mode */
function mcrypt_check_sanity() {
$modes = mcrypt_list_modes();
$algorithms = mcrypt_list_algorithms();
foreach ($algorithms as $cipher) {
if(mcrypt_module_self_test($cipher)) {
print $cipher." ok.<br />\n";
} else {
print $cipher." not ok.<br />\n";
}
foreach ($modes as $mode) {
if($mode == 'stream') {
$result = "not tested";
} else if(mcrypt_test_module_mode($cipher,$mode)) {
$result = "ok";
} else {
$result = "not ok";
}
print $cipher." in mode ".$mode." ".$result."<br />\n";
mcrypt_module_close($td);
}
}
}
// a variant on the example posted in mdecrypt_generic
function mcrypt_test_module_mode($module,$mode) {
/* Data */
$key = 'this is a very long key, even too long for the cipher';
$plain_text = 'very important data';
/* Open module, and create IV */
$td = mcrypt_module_open($module, '',$mode, '');
$key = substr($key, 0, mcrypt_enc_get_key_size($td));
$iv_size = mcrypt_enc_get_iv_size($td);
$iv = mcrypt_create_iv($iv_size, MCRYPT_RAND);
/* Initialize encryption handle */
if (mcrypt_generic_init($td, $key, $iv) != -1) {
/* Encrypt data */
$c_t = mcrypt_generic($td, $plain_text);
mcrypt_generic_deinit($td);
// close the module
mcrypt_module_close($td);
/* Reinitialize buffers for decryption */
/* Open module */
$td = mcrypt_module_open($module, '', $mode, '');
$key = substr($key, 0, mcrypt_enc_get_key_size($td));
mcrypt_generic_init($td, $key, $iv);
$p_t = trim(mdecrypt_generic($td, $c_t)); //trim to remove padding
/* Clean up */
mcrypt_generic_end($td);
mcrypt_module_close($td);
}
if (strncmp($p_t, $plain_text, strlen($plain_text)) == 0) {
return TRUE;
} else {
return FALSE;
}
}
// function call:
mcrypt_check_sanity();
?>
Apologies for any confusion the previous version may have caused. The only working mode listed was
ecb, since it does not use an IV.
----
Manual Page -- http://www.php.net/manual/en/ref.mcrypt.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+40397
Delete -- http://master.php.net/manage/user-notes.php?action=delete+40397&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+40397&report=yes
Search -- http://master.php.net/manage/user-notes.php