Sample code for 30+ languages & platforms
Zig

Duplicate PHP's openssl_encrypt and openssl_random_pseudo_bytes

See more OpenSSL Examples

Demonstrates how to duplicate PHP's openssl_encrypt function. (https://www.php.net/manual/en/function.openssl-encrypt.php)

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    // Duplicates thw following PHP script:

    // $text = "This is a test";
    // $passphrase = "my password";
    // $iv = openssl_random_pseudo_bytes(openssl_cipher_iv_length("AES-256-CBC"));
    // $crypted = base64_encode($iv.openssl_encrypt($text, "AES-256-CBC", $passphrase, OPENSSL_RAW_DATA, $iv));
    // echo $crypted;

    const crypt = try chilkat.Crypt2.init();
    defer crypt.deinit();

    const text = "This is a test";
    const passphrase = "my password";

    // AES is a block cipher.  The IV size for any block cipher is the size of the block, which is defined by the encryption algorithm.
    // For AES, the block size is always 16 bytes, regardless of key size (i.e. 128-bits, 192-bits, or 256-bits).
    // Therefore, generate 16 random bytes for the IV.
    crypt.setEncodingMode("base64");
    const iv_base64 = try crypt.genRandomBytesENC(alloc, 16);

    std.debug.print("Generated IV = {s}\n", .{iv_base64});

    // Because we're doing AES-256-CBC, the key length must be 256-bits (i.e. 32 bytes).
    // Given that our passphrase is a us-ascii string that can be shorter or longer than 32-bytes, we need to
    // somehow transform the passphrase to a 32-byte secret key.  We need to know what openssl_encrypt does.
    // Here's the answer from the openssl_encrypt documentation:
    //
    // "If the passphrase is shorter than expected, it is silently padded with NUL characters;
    // if the passphrase is longer than expected, it is silently truncated."

    // OK.... so let's pad or shorten to get a 32-byte key.
    const bd_key = try chilkat.BinData.init();
    defer bd_key.deinit();
    bd_key.appendString(passphrase, "utf-8") catch {};

    const sz = bd_key.getNumBytes();
    if (sz > 32) {
        bd_key.removeChunk(32, sz - 32) catch {};
    } else {
        bd_key.clear() catch {};
        bd_key.appendPadded(passphrase, "utf-8", false, 32) catch {};
    }

    // Setup for encryption.
    crypt.setCryptAlgorithm("aes");
    crypt.setKeyLength(256);
    crypt.setEncodedIV(iv_base64, "base64");
    crypt.setEncodedKey(try bd_key.getEncoded(alloc, "base64"), "base64");

    // Encrypt and base64 encode.
    const cipher_text64 = try crypt.encryptStringENC(alloc, text);

    // The PHP code fragment above returns the base64 encoded bytes of the IV and the encrypted text.
    // So let's do that..
    const bd = try chilkat.BinData.init();
    defer bd.deinit();
    bd.appendEncoded(iv_base64, "base64") catch {};
    bd.appendEncoded(cipher_text64, "base64") catch {};
    const result = try bd.getEncoded(alloc, "base64");

    std.debug.print("result = {s}\n", .{result});

    // Sample output:
    // dN0vS1O0cWi5BbLAAY+NTf7bs3S27xzPf11RkG47sjs=

    // Now let's decrypt from the output...

    // Setup for decryption.
    crypt.setCryptAlgorithm("aes");
    crypt.setKeyLength(256);
    crypt.setEncodedKey(try bd_key.getEncoded(alloc, "base64"), "base64");

    const bd_result = try chilkat.BinData.init();
    defer bd_result.deinit();
    bd_result.appendEncoded(result, "base64") catch {};
    crypt.setEncodedIV(try bd_result.getEncodedChunk(alloc, 0, 16, "base64"), "base64");

    // Remove the IV (first 16 bytes) from the result.
    bd_result.removeChunk(0, 16) catch {};
    try crypt.decryptBd(bd_result);
    const original_text = try bd_result.getString(alloc, "utf-8");

    std.debug.print("original text = {s}\n", .{original_text});
}