`EVP_CIPHER_CTX_get_iv_length()` reports `16` for AES-ECB with `symcryptprovider`
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 68/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Tranquilla
- Stack tecnologico
- c
- Ambito
- cryptography, security
Direzione di ricerca
Inizia con l’implementazione del provider del cifrario AES in SymCrypt-OpenSSL e usa il Plain C Reproducer fornito con OpenSSL 3. Confronta la lunghezza dell’IV del contesto inizializzato per AES-ECB con il valore a livello di cifrario e con il provider predefinito. Il lavoro è completato quando symcryptprovider restituisce 0 sia per EVP_CIPHER_get_iv_length() sia per EVP_CIPHER_CTX_get_iv_length().
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
When using SymCrypt-OpenSSL’s OpenSSL 3 provider (symcryptprovider), an initialized AES-ECB cipher context reports an IV length of 16 via EVP_CIPHER_CTX_get_iv_length().
ECB mode does not use an IV, so the expected context IV length is 0. OpenSSL’s default/FIPS providers report 0 for AES-ECB. The SymCrypt-OpenSSL provider appears to report the AES block size or a generic AES context IV buffer length instead.
This looks like an OpenSSL provider metadata compatibility issue in SymCrypt-OpenSSL, not an issue in the core SymCrypt primitive.
Environment
Observed on Azure Linux 3 with:
- OpenSSL:
3.3.5 - Provider module:
symcryptprovider.so - SymCrypt provider version:
1.9.5 - Provider path: ossl-modules
Expected Behavior
For AES-ECB:
EVP_CIPHER_get_iv_length(cipher) == 0
EVP_CIPHER_CTX_get_iv_length(ctx) == 0
ECB has no IV, so both cipher-level and initialized-context-level IV length should be zero.
Actual Behavior
With symcryptprovider:
EVP_CIPHER_get_iv_length(cipher) == 0
EVP_CIPHER_CTX_get_iv_length(ctx) == 16
The cipher-level metadata is correct, but the initialized context reports 16.
Why This Matters
This can break applications or test suites that use OpenSSL EVP metadata to validate cipher parameters. Even if AES-ECB encryption/decryption itself works correctly, the context metadata is inconsistent with OpenSSL provider behavior and with ECB semantics.
This may cause callers to incorrectly believe AES-ECB requires or has an IV after initialization.
Plain C Reproducer
#include <openssl/evp.h>
#include <openssl/provider.h>
#include <stdio.h>
#include <string.h>
static int test_provider(const char *provider_name)
{
int ret = 1;
OSSL_LIB_CTX *libctx = NULL;
OSSL_PROVIDER *provider = NULL;
EVP_CIPHER *cipher = NULL;
EVP_CIPHER_CTX *ctx = NULL;
unsigned char key[16];
memset(key, 0, sizeof(key));
libctx = OSSL_LIB_CTX_new();
if (libctx == NULL) {
fprintf(stderr, "OSSL_LIB_CTX_new failed\n");
goto cleanup;
}
provider = OSSL_PROVIDER_load(libctx, provider_name);
if (provider == NULL) {
fprintf(stderr, "OSSL_PROVIDER_load(%s) failed\n", provider_name);
goto cleanup;
}
cipher = EVP_CIPHER_fetch(libctx, "AES-128-ECB", NULL);
if (cipher == NULL) {
fprintf(stderr, "EVP_CIPHER_fetch(AES-128-ECB) failed for provider %s\n", provider_name);
goto cleanup;
}
ctx = EVP_CIPHER_CTX_new();
if (ctx == NULL) {
fprintf(stderr, "EVP_CIPHER_CTX_new failed\n");
goto cleanup;
}
if (EVP_CipherInit_ex2(ctx, cipher, key, NULL, 1, NULL) != 1) {
fprintf(stderr, "EVP_CipherInit_ex2 failed for provider %s\n", provider_name);
goto cleanup;
}
printf("provider: %s\n", provider_name);
printf("EVP_CIPHER_get0_name: %s\n", EVP_CIPHER_get0_name(cipher));
printf("EVP_CIPHER_get_iv_length: %d\n", EVP_CIPHER_get_iv_length(cipher));
printf("EVP_CIPHER_CTX_get_iv_length: %d\n", EVP_CIPHER_CTX_get_iv_length(ctx));
printf("\n");
ret = 0;
cleanup:
EVP_CIPHER_CTX_free(ctx);
EVP_CIPHER_free(cipher);
OSSL_PROVIDER_unload(provider);
OSSL_LIB_CTX_free(libctx);
return ret;
}
int main(void)
{
int ret = 0;
ret |= test_provider("default");
ret |= test_provider("symcryptprovider");
return ret;
}
Build
cc -Wall -Wextra -o aes_ecb_ivlen_repro aes_ecb_ivlen_repro.c -lcrypto
Run
If the provider is not in OpenSSL’s default module path:
OPENSSL_MODULES=/usr/lib64/ossl-modules ./aes_ecb_ivlen_repro
Otherwise:
./aes_ecb_ivlen_repro
Observed Output
Example output:
provider: default
EVP_CIPHER_get0_name: AES-128-ECB
EVP_CIPHER_get_iv_length: 0
EVP_CIPHER_CTX_get_iv_length: 0
provider: symcryptprovider
EVP_CIPHER_get0_name: AES-128-ECB
EVP_CIPHER_get_iv_length: 0
EVP_CIPHER_CTX_get_iv_length: 16
Suggested Fix
In SymCrypt-OpenSSL’s AES cipher provider implementation, ensure the context IV length returned for ECB mode is 0.
The provider likely needs to special-case ECB when returning the cipher context IV length, rather than returning the AES block size or a generic AES IV buffer size.
- Lingua principale
- C
- Stelle
- 81
- Fork
- 16
- Merge medio
- 22h 34m
- PR unite (30g)
- 2
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di microsoft/SymCrypt-OpenSSL
-
requests with cipher(DHE-RSA-AES256-GCM-SHA384) fail with internal errorForse di nuovo libera @mamckee l’ha presa 340 giorni fa e non c’è nessuna pull request aperta. Apertainvestigate
microsoft/SymCrypt-OpenSSL#151 · 1 commento · 1 assegnatario ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 38/100
microsoft/SymCrypt-OpenSSL#114 · 2 commenti ·
Tutte le issue di microsoft/SymCrypt-OpenSSL
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
libsdl-org/SDL#16444 ·
I maintainer di solito rispondono entro 1 giorno
-
bug Component component: net
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
RT-Thread/rt-thread#11852 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
MiSTer-devel/ao486_MiSTer#243 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 66/100
siderolabs/pkgs#1710 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
qmk/qmk_firmware#26498 ·
I maintainer di solito rispondono entro 1 giorno