Repository navigation
openssl_seal()/_open() is not able to handle gcm cipers, e.g. aes-256-gcm #7737
Description
Activity
@bukka, could you please clarify whether this is a bug, or a feature request, or a documentation issue?
Well, AFAIK PHP's openssl_seal() is not able to use the gcm-ciphers. So probably
- it should be documented
- one might regard this as a missing feature
- as
openssl_seal()does not complain (return value is true) this is also a bug. Arguably, the encoding does succeed. Its just that there is no chance to decode the sealed data without the authentication tag.
There is also an attempt to use openssl_seal() with
aes-256-gcmwithin the Nextcloud-project: nextcloud/server#25551I don't think there's any issue in OpenSSL so you can probably close that linked ticket in OpenSSL. This is just a missing functionality in PHP and it's really a feature request. Basically
EVP_Seal*are just wrappers aroundEVP_Encrypt*that allows encrypting the key with the supplied pkey. What PHP doesn't do is to provide a way to return a tag. Although you could probably write your version of sealing in PHP to give you the same functionality ( you might get an idea when you look to https://github.com/openssl/openssl/blob/defe51c178e3dc9f07514c179121021fd78691b4/crypto/evp/p_seal.c ). That said we could possibly add extra parameters toopenssl_sealto return tag and also extendopenssl_openaccordingly. So that's why this should be a feature request.Reacted by Christoph M. BeckerSo then. Kind of a missing feature.
You are probably right that an extra parameter
string &$tagor so is more in the spirit of the current interface than simply appending the tag to the encrypted keys.I am still tempted to interpret the current state as a documentation bug. It is not so clear from reading the manual that the the ...-gcm ciphes to not work out of the box. And it still feels a little bit weird that
openssl_seal()very happily accepts the ...-gcm cipher just to produce something which cannot be decrypted again.I agree that it should be noted in docs but doc bugs should be reported to https://github.com/php/doc-en . So for this repo, it's just a feature request... :)
Agreed. I have just filed an issue which, well, is just a link to this issue.
@bukka Hello, I see you are listed as maintainer for the openssl extension.
Regarding this issue:
- How hard is it to fix? Is it just a matter of adding the parameter or is there a bigger refactoring needed?
- If it was fixed, would it be backported or would it be PHP>8.2 only?
- Is the
openssl_sealfunction somehow deprecated? I see negative comments on https://www.php.net/manual/function.openssl-seal.php on both use of RC4 and PKCS1 v1.5. Does it make sense to use this function with newer ciphers in your opinion, or is there another more suited solution?
- $key) { $decrypted = null; // ;) $unsealedKey = $sealedKeys[$i]; // Use openssl_decrypt() for GCM mode if ($cipherAlgo === 'aes-256-gcm') { $result = openssl_decrypt($sealedData, $cipherAlgo, $unsealedKey, OPENSSL_RAW_DATA, $iv, $tag); echo "OPEN: " . $result . PHP_EOL; echo "RESULT: " . ($result !== false ? 'true' : 'false') . PHP_EOL; } else { $result = openssl_open($sealedData, $decrypted, $unsealedKey, $key, $cipherAlgo, $iv); echo "OPEN: " . $decrypted . PHP_EOL; echo "RESULT: " . ($result ? 'true' : 'false') . PHP_EOL; } $result = openssl_private_decrypt($unsealedKey, $unsealedKey, $key); echo "UNSEAL: " . bin2hex($unsealedKey) . PHP_EOL; echo "RESULT: " . ($result ? 'true' : 'false') . PHP_EOL; echo "DECRYPT: " . openssl_decrypt($sealedData, $cipherAlgo, $unsealedKey, OPENSSL_RAW_DATA, $iv) . PHP_EOL; } echo PHP_EOL; }
- added a commit that references this issue
on Dec 11, 2025 - added a commit that references this issue
on Dec 12, 2025 - added 2 commits that reference this issue
on Dec 13, 2025 Reopened because the PR was reverted
Description
The following code:
Resulted in this output:
But I expected this output instead:
The point is that the gcm-cipher need the authentication tag for decrypting the data. This however does not seem to be saved by the
openssl_seal()function. I have also placed a question in the OpenSSL issue tracker: openssl/openssl#17235PHP Version
PHP 8.0.13 (cli) (built: Nov 27 2021 17:17:19) ( ZTS )
Operating System
Gentoo Linux 5.15.6, but should not matter