From: x1 Date: 2005-09-28T10:47:43+09:00 Subject: Re: How do I (really) encrypt a string in ruby? :- ) Absolutely Excellent!! You sir, are the man! On 9/27/05, NAKAMURA, Hiroshi wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Hi, > > Michal Suchanek wrote: > > However, encrypting 2.0M file gives 2.1M file. > > It may be caused by PKCS#5 padding. > > > Since doing encryption in C makes 2.0M ciphertext from 2.0M plaintext, > > and it is also possible to decrypt the 2.0M ciphertext to the original > > plaintext, something is rotten here. > > > > Am I missing something? > > > > require "openssl" > > > > CHLEN = 256 > > KBITS = 256 > > KLEN = 32 > > IVLEN = 16 # God knows why > > AES is a 128 bits (16 bytes) block cipher. > > > f=File.open("testkey"); > > key=f.read(KLEN) > > f.close > > f=File.open("testiv") > > iv=f.read(IVLEN) > > f.close > > > while (chunk=STDIN.read(CHLEN)) > > cipher=OpenSSL::Cipher::Cipher.new("AES-256-CBC") > > cipher.encrypt(key,iv) > > cipher.key=key > > cipher.iv=iv > > STDOUT << cipher.update(chunk) > > STDOUT << cipher.final() > > end > > This block should be: > > cipher=OpenSSL::Cipher::Cipher.new("AES-256-CBC") > cipher.encrypt(key,iv) > cipher.padding=0 # avoid PKCS#5 padding > cipher.key=key > cipher.iv=iv > ciphertext = [] > while (chunk=STDIN.read(CHLEN)) > ciphertext << cipher.update(chunk) > end > ciphertext << cipher.final() rescue nil # no need to call final if > padding = 0 > print ciphertext.join > > Regards, > // NaHi > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.1 (Cygwin) > > iD8DBQFDOegcf6b33ts2dPkRAul3AKCZStaQkGlmrPmWdNtDtlz5hTWr+wCgkxTg > YNdIRFCn/OZ7KB4zFcBYMRA= > =OSin > -----END PGP SIGNATURE----- > >