From: David x Callaway Date: 2007-03-24T02:27:24+09:00 Subject: Re: Ruby and Cryptography > Updated documentation is available at > http://technorama.net/~oss/ruby/openssl/doc/ > > The documention isn't complete. > but it is a *lot* better than the standard lib docs ;-). with aid from the documention above and looking at the c source for ruby openssl, I wrote the code below (I left out error checking for brevity here) which looks reasonable for encrypting/decrypting from streams. it "works", meaning I can encrypt a stream and recover it, and it is quite fast, ~1 sec to encrypt a 20MB file vs more than one hour for Crypt to do the same. questions: 1) is pkcs5_keyivgen() the way to go rather than hashing (password string + salt) and then using that as the key with OpenSSL::Cipher::Cipher as EzCrypto does? 2) how can I make the encrypted output compatible with what I get from using openssl directly, e.g. openssl aes-128-cbc -e -in xxx.txt -out out.bin \ -pass pass:aaaabbbbccccdddd -salt -S 6161616161616161 -p openssl includes the salt string in the encrypted output, so I tried -nosalt and other things like providing the key binary directly, but no matter what the encrypted file did not match either the output from the code below or code using EzCrypto (EzCrypto didn't match openssl either), so I could not decrypt openssl output nor could it decrypt mine. since the purpose of encryption is to make the content secure I would feel a lot warmer and fuzzier if I got interoperable output. -------- code follows ----------- def process_stream(action,src,target) begin cipher = Cipher.new(@cipher_name) if action == :encrypt cipher.encrypt.pkcs5_keyivgen(@password,@salt) elsif action == :decrypt cipher.decrypt.pkcs5_keyivgen(@password,@salt) else raise "programming error: unsupported action \"#{action}\"" end loop do buffer = src.read(@block_size) or break target << cipher.update(buffer) end target << cipher.final rescue Exception => e @error = e.to_s return false end return true end -- Posted via http://www.ruby-forum.com/.