NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #5246 most downloaded on Packagist
Strong cryptography tools and password hashing
Last release 7 years ago
no release in 18 months
Release timing varies
gaps range from 4 weeks to 13 months
Rarely documented
notes for 9 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
68 releases · first in 2012
Added #60 adds support for PHP 7.3. Changed Nothing. Deprecated Nothing. Removed Nothing. Fixed Nothing.
Added #52 adds support for PHP 7.2. Changed #55 updates Zend\Crypt\Hmac to use hash_hmac_algos instead of hmac_algos when it is present. #50 updates a
One column per quarter.
Added #42 Added the CTR mode for OpenSSL. Deprecated Nothing. Removed Nothing. Fixed #48 Incorrect Rsa type declaration in Hybrid constructor.
Added #38 Support of GCM and CCM encryption mode for OpenSSL with PHP 7.1+ Deprecated Nothing. Removed Nothing. Fixed Nothing.
Added #32 adds a new Hybrid encryption utility, to allow OpenPGP-like encryption/decryption of messages using OpenSSL. See the documentation for detai
Added #22 adds a requirement on ext/mbstring in order to install successfully. #25 adds a new symmetric encryption adapter for the OpenSSL extension;
ext/mbstring in order to install successfully.Zend\Crypt\Password\Bcrypt::benchmarkCost(), which allows you to find the maximum cost value possible for your hardware within a 50ms timeframe.Zend\Crypt\PublicKey\RsaOptions class, openssl_padding (or setOpensslPadding(); this is now consumed in Zend\Crypt\PublicKey\Rsa::encrypt() and Zend\Crypt\PublicKey\Rsa::decrypt(), instead of the optional $padding argument.$padding argument from each of Zend\Crypt\PublicKey\Rsa's encrypt() and decrypt() methods; you can now specify the value via the RsaOptions.substr() and strlen() to use mb_substr() and mb_strlen(), respectively. This provides better security with binary values.Zend\Crypt\Password\Bcrypt implementation to use password_hash() and password_verify() internally, as they are supported in all PHP versions we support.DiffieHellman publickey implementation to initialize the BigInteger adapter from zend-math as the first operation of its constructor, fixing a fatal error that occurs when binary data is provided.Removes the (development) dependency on zend-config; tests that used it previously have been updated to use ArrayObject, which implements the same beh
ArrayObject, which implements the same
behavior being tested.AbstractPluginManager.…of PKCS1v1.5 padding. This padding has a known vulnerability, the Bleichenbacher's chosen-ciphertext attack, which can be used to recover an RSA priva…
ZF2015-10: Zend\Crypt\PublicKey\Rsa\PublicKey has a call to openssl_public_encrypt()
which used PHP's default $padding argument, which specifies
OPENSSL_PKCS1_PADDING, indicating usage of PKCS1v1.5 padding. This padding
has a known vulnerability, the
Bleichenbacher's chosen-ciphertext attack,
which can be used to recover an RSA private key. This release contains a patch
that changes the padding argument to use OPENSSL_PKCS1_OAEP_PADDING.
Users upgrading to this version may have issues decrypting previously stored
values, due to the change in padding. If this occurs, you can pass the
constant OPENSSL_PKCS1_PADDING to a new $padding argument in
Zend\Crypt\PublicKey\Rsa::encrypt() and decrypt() (though typically this
should only apply to the latter):
$decrypted = $rsa->decrypt($data, $key, $mode, OPENSSL_PKCS1_PADDING);
where $rsa is an instance of Zend\Crypt\PublicKey\Rsa.
(The $key and $mode argument defaults are null and
Zend\Crypt\PublicKey\Rsa::MODE_AUTO, if you were not using them previously.)
We recommend re-encrypting any such values using the new defaults.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
…of PKCS1v1.5 padding. This padding has a known vulnerability, the Bleichenbacher's chosen-ciphertext attack, which can be used to recover an RSA priva…
ZF2015-10: Zend\Crypt\PublicKey\Rsa\PublicKey has a call to openssl_public_encrypt()
which used PHP's default $padding argument, which specifies
OPENSSL_PKCS1_PADDING, indicating usage of PKCS1v1.5 padding. This padding
has a known vulnerability, the
Bleichenbacher's chosen-ciphertext attack,
which can be used to recover an RSA private key. This release contains a patch
that changes the padding argument to use OPENSSL_PKCS1_OAEP_PADDING.
Users upgrading to this version may have issues decrypting previously stored
values, due to the change in padding. If this occurs, you can pass the
constant OPENSSL_PKCS1_PADDING to a new $padding argument in
Zend\Crypt\PublicKey\Rsa::encrypt() and decrypt() (though typically this
should only apply to the latter):
$decrypted = $rsa->decrypt($data, $key, $mode, OPENSSL_PKCS1_PADDING);
where $rsa is an instance of Zend\Crypt\PublicKey\Rsa.
(The $key and $mode argument defaults are null and
Zend\Crypt\PublicKey\Rsa::MODE_AUTO, if you were not using them previously.)
We recommend re-encrypting any such values using the new defaults.
hotfix/5
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →