Issue #6980 has been updated by stouset (Stephen Touset).

File openssl_aead_ciphers.patch added

Sorry, patch included unintentional whitespace changes. Reuploaded without whitespace changes.
----------------------------------------
Feature #6980: OpenSSL support for AEAD additional authenticated data and tags
https://bugs.ruby-lang.org/issues/6980#change-29178

Author: stouset (Stephen Touset)
Status: Open
Priority: Normal
Assignee: 
Category: ext
Target version: 1.9.3


=begin
I've added support to OpenSSL::Cipher to support AEAD modes of operation. AEAD modes allow for plaintext additional authentication data to be combined with a ciphertext to generate a "tag" (e.g., a MAC). This tag can then be verified during decryption to ensure the secret key, nonce (IV), additional authentication data, ciphertext, and tag have not been changed or manipulated.

Usage can be inferred through documentation and tests.

  
 cipher = OpenSSL::Cipher.new('aes-256-gcm')
 cipher.encrypt
 cipher.key = 'key'
 cipher.iv = 'iv'
 cipher.aad = 'aad'
  
 ct = cipher.update('plain')
 tag = cipher.gcm_tag
 
 cipher.reset
 cipher.decrypt
 cipher.key = 'key'
 cipher.iv = 'iv'
 cipher.gcm_tag = 'tag'
 cipher.aad = 'aad'

 cipher.update(ct) + cipher.verify + cipher.final # => 'plain'

 cipher.reset
 cipher.decrypt
 cipher.key = 'key'
 cipher.iv = 'iv'
 cipher.gcm_tag = 'tag'
 cipher.aad = 'aad'

 cipher.update(ct[0..-2] << ct[-1].succ) + cipher.verify + cipherfinal # => OpenSSL::Cipher::CipherError
=end


-- 
http://bugs.ruby-lang.org/