Rust
Rust
Duplicate PHP's openssl_encrypt and openssl_random_pseudo_bytes
See more OpenSSL Examples
Demonstrates how to duplicate PHP's openssl_encrypt function. (https://www.php.net/manual/en/function.openssl-encrypt.php)Chilkat Rust Downloads
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
// Duplicates thw following PHP script:
// $text = "This is a test";
// $passphrase = "my password";
// $iv = openssl_random_pseudo_bytes(openssl_cipher_iv_length("AES-256-CBC"));
// $crypted = base64_encode($iv.openssl_encrypt($text, "AES-256-CBC", $passphrase, OPENSSL_RAW_DATA, $iv));
// echo $crypted;
let crypt = chilkat::Crypt2::new();
let text = "This is a test".to_string();
let passphrase = "my password".to_string();
// AES is a block cipher. The IV size for any block cipher is the size of the block, which is defined by the encryption algorithm.
// For AES, the block size is always 16 bytes, regardless of key size (i.e. 128-bits, 192-bits, or 256-bits).
// Therefore, generate 16 random bytes for the IV.
crypt.set_encoding_mode("base64");
let iv_base64 = crypt.gen_random_bytes_enc(16).unwrap_or_default();
println!("Generated IV = {}", iv_base64);
// Because we're doing AES-256-CBC, the key length must be 256-bits (i.e. 32 bytes).
// Given that our passphrase is a us-ascii string that can be shorter or longer than 32-bytes, we need to
// somehow transform the passphrase to a 32-byte secret key. We need to know what openssl_encrypt does.
// Here's the answer from the openssl_encrypt documentation:
//
// "If the passphrase is shorter than expected, it is silently padded with NUL characters;
// if the passphrase is longer than expected, it is silently truncated."
// OK.... so let's pad or shorten to get a 32-byte key.
let bd_key = chilkat::BinData::new();
let _ = bd_key.append_string(&passphrase, "utf-8");
let sz = bd_key.num_bytes();
if sz > 32 {
let _ = bd_key.remove_chunk(32, sz - 32);
} else {
let _ = bd_key.clear();
let _ = bd_key.append_padded(&passphrase, "utf-8", false, 32);
}
// Setup for encryption.
crypt.set_crypt_algorithm("aes");
crypt.set_key_length(256);
crypt.set_encoded_iv(&iv_base64, "base64");
crypt.set_encoded_key(&bd_key.get_encoded("base64").unwrap_or_default(), "base64");
// Encrypt and base64 encode.
let cipher_text64 = crypt.encrypt_string_enc(&text).unwrap_or_default();
// The PHP code fragment above returns the base64 encoded bytes of the IV and the encrypted text.
// So let's do that..
let bd = chilkat::BinData::new();
let _ = bd.append_encoded(&iv_base64, "base64");
let _ = bd.append_encoded(&cipher_text64, "base64");
let result = bd.get_encoded("base64").unwrap_or_default();
println!("result = {}", result);
// Sample output:
// dN0vS1O0cWi5BbLAAY+NTf7bs3S27xzPf11RkG47sjs=
// Now let's decrypt from the output...
// Setup for decryption.
crypt.set_crypt_algorithm("aes");
crypt.set_key_length(256);
crypt.set_encoded_key(&bd_key.get_encoded("base64").unwrap_or_default(), "base64");
let bd_result = chilkat::BinData::new();
let _ = bd_result.append_encoded(&result, "base64");
crypt.set_encoded_iv(&bd_result.get_encoded_chunk(0, 16, "base64").unwrap_or_default(), "base64");
// Remove the IV (first 16 bytes) from the result.
let _ = bd_result.remove_chunk(0, 16);
let _ = crypt.decrypt_bd(&bd_result).is_ok();
let original_text = bd_result.get_string("utf-8").unwrap_or_default();
println!("original text = {}", original_text);