Sample code for 30+ languages & platforms
Xbase++

Duplicate PHP's openssl_encrypt and openssl_random_pseudo_bytes

See more OpenSSL Examples

Demonstrates how to duplicate PHP's openssl_encrypt function. (https://www.php.net/manual/en/function.openssl-encrypt.php)

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oCrypt
LOCAL cText
LOCAL cPassphrase
LOCAL cIvBase64
LOCAL oBdKey
LOCAL nSz
LOCAL cCipherText64
LOCAL oBd
LOCAL cResult
LOCAL oBdResult
LOCAL cOriginalText

nSuccess := 0

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  Duplicates thw following PHP script:

//  $text = "This is a test";
//  $passphrase = "my password";
//  $iv = openssl_random_pseudo_bytes(openssl_cipher_iv_length("AES-256-CBC"));
//  $crypted = base64_encode($iv.openssl_encrypt($text, "AES-256-CBC", $passphrase, OPENSSL_RAW_DATA, $iv));
//  echo $crypted;

oCrypt := CreateObject("Chilkat.Crypt2")

cText := "This is a test"
cPassphrase := "my password"

//  AES is a block cipher.  The IV size for any block cipher is the size of the block, which is defined by the encryption algorithm. 
//  For AES, the block size is always 16 bytes, regardless of key size (i.e. 128-bits, 192-bits, or 256-bits).
//  Therefore, generate 16 random bytes for the IV.
oCrypt:EncodingMode := "base64"
cIvBase64 := oCrypt:GenRandomBytesENC(16)

? "Generated IV = " + cIvBase64

//  Because we're doing AES-256-CBC, the key length must be 256-bits (i.e. 32 bytes).
//  Given that our passphrase is a us-ascii string that can be shorter or longer than 32-bytes, we need to 
//  somehow transform the passphrase to a 32-byte secret key.  We need to know what openssl_encrypt does.
//  Here's the answer from the openssl_encrypt documentation:
//  
//  "If the passphrase is shorter than expected, it is silently padded with NUL characters; 
//  if the passphrase is longer than expected, it is silently truncated."

//  OK.... so let's pad or shorten to get a 32-byte key.
oBdKey := CreateObject("Chilkat.BinData")
oBdKey:AppendString(cPassphrase, "utf-8")

nSz := oBdKey:NumBytes
IF (nSz > 32)
    oBdKey:RemoveChunk(32, nSz - 32)
ELSE
    oBdKey:Clear()
    oBdKey:AppendPadded(cPassphrase, "utf-8", 0, 32)
ENDIF

//  Setup for encryption.
oCrypt:CryptAlgorithm := "aes"
oCrypt:KeyLength := 256
oCrypt:SetEncodedIV(cIvBase64, "base64")
oCrypt:SetEncodedKey(oBdKey:GetEncoded("base64"), "base64")

//  Encrypt and base64 encode.
cCipherText64 := oCrypt:EncryptStringENC(cText)

//  The PHP code fragment above returns the base64 encoded bytes of the IV and the encrypted text.
//  So let's do that..
oBd := CreateObject("Chilkat.BinData")
oBd:AppendEncoded(cIvBase64, "base64")
oBd:AppendEncoded(cCipherText64, "base64")
cResult := oBd:GetEncoded("base64")

? "result = " + cResult

//  Sample output:
//  dN0vS1O0cWi5BbLAAY+NTf7bs3S27xzPf11RkG47sjs=

//  Now let's decrypt from the output...

//  Setup for decryption.
oCrypt:CryptAlgorithm := "aes"
oCrypt:KeyLength := 256
oCrypt:SetEncodedKey(oBdKey:GetEncoded("base64"), "base64")

oBdResult := CreateObject("Chilkat.BinData")
oBdResult:AppendEncoded(cResult, "base64")
oCrypt:SetEncodedIV(oBdResult:GetEncodedChunk(0, 16, "base64"), "base64")

//  Remove the IV (first 16 bytes) from the result.
oBdResult:RemoveChunk(0, 16)
nSuccess := oCrypt:DecryptBd(oBdResult)
cOriginalText := oBdResult:GetString("utf-8")

? "original text = " + cOriginalText

oCrypt:destroy()
oBdKey:destroy()
oBd:destroy()
oBdResult:destroy()