Skip to content

Deprecated warnings on PHP 7.1 #55

Description

@shadowhand

When running RandomLib 1.2.0 under PHP 7.1, the following warning appears:

Function mcrypt_module_open() is deprecated

https://wiki.php.net/rfc/mcrypt-viking-funeral

Activity

  1. byrnedo commented on Nov 3, 2016

    @byrnedo

    Hi, Any idea when this will be fixed?

  2. shadowhand commented on Nov 3, 2016

    @shadowhand
    Author

    Sounds like never, since random_bytes effectively replaces it.

  3. byrnedo commented on Nov 3, 2016

    @byrnedo

    Sorry, how do you mean?

    Edit: Ah ok, you mean effectively replaces this lib in 7+?

  4. shadowhand commented on Nov 3, 2016

    @shadowhand
    Author

    It doesn't generate as much variation, but this works equally well:

    $length = 32;
    $random = substr(bin2hex(random_bytes($length)), 0, $length);
  5. it-can commented on Jan 8, 2017

    @it-can

    Please fix this...

  6. abada commented on Jan 11, 2017

    @abada

    Please fix it !

  7. romeritoCL commented on Jan 24, 2017

    @romeritoCL

    +1

  8. JanisGruzis commented on Jan 24, 2017

    @JanisGruzis

    +1

  9. codeator commented on Feb 11, 2017

    @codeator

    +1

  10. wernersbacher commented on Feb 23, 2017

    @wernersbacher

    +1

  11. spidgorny commented on Feb 23, 2017

    @spidgorny

    I was also stuck with this and had to make it working ASAP. I'm no-way a security specialist - I only have a vague idea of what I'm doing. Improvements are welcome.

    OpenSSLMixer.php

  12. mosiyash commented on Mar 9, 2017

    @mosiyash

    +1

  13. Tjab commented on Apr 5, 2017

    @Tjab

    Somehow, my error_reporting is set to -1, even though my php.ini shows E_ALL & ~E_DEPRECATED. Might be the issue for other people who can't continue with this...

  14. ramsey commented on Apr 5, 2017

    @ramsey
    Collaborator

    In PHP 7.2, the mcrypt library will be removed from core completely. There is a PECL extension for mcrypt, but you cannot install it on PHP 7.1, so you're left with a deprecation warning until 7.2.

    We should update this lib to check for the extension and only provide mcrypt if the extension is present.

  15. ramsey commented on Apr 5, 2017

    @ramsey
    Collaborator

    I've just opened this request on bugs.php.net to ask that pecl/mcrypt be installable on PHP 7.1. https://bugs.php.net/bug.php?id=74375

  16. 2 remaining items

  17. levelfivehub commented on Jun 29, 2017

    @levelfivehub

    +1000000000

  18. techi602 commented on Jun 29, 2017

    @techi602

    I had to abandon this library and use openssl_random_pseudo_bytes

  19. SamuelMoraesF commented on Aug 4, 2017

    @SamuelMoraesF

    +1

  20. jazithedev commented on Aug 8, 2017

    @jazithedev

    +1

  21. paragonie-scott commented on Aug 13, 2017

    @paragonie-scott
  22. pavarnos commented on Aug 16, 2017

    @pavarnos

    If we change https://github.com/ircmaxell/RandomLib/blob/master/lib/RandomLib/AbstractMcryptMixer.php#L67 to

    return version_compare(PHP_VERSION, '7.1') < 0 && extension_loaded('mcrypt');

    would that fix it?

  23. tarlepp commented on Sep 24, 2017

    @tarlepp

    Any progress with this one ?

  24. the94air commented on Oct 5, 2017

    @the94air

    A lot of people are using this package. It is so sad that it is not working any more.

  25. paragonie-scott commented on Oct 5, 2017

    @paragonie-scott

    I'm debating forking it. It's been nigh impossible to get any feedback from Anthony for... going on a year now... from any venue or channel.

  26. the94air commented on Oct 5, 2017

    @the94air

    I found an alternative here https://github.com/antonioribeiro/random. He is using random_bytes() and random_int()

  27. tarlepp commented on Oct 5, 2017

    @tarlepp

    @ircmaxell any updates with this ?

  28. paragonie-scott commented on Oct 5, 2017

    @paragonie-scott

    In the off-chance that it takes months or years before we hear back from @ircmaxell, I've gone ahead with a fork of this library.

    https://github.com/paragonie/RandomLib

    It solves this issue, by not loading mcrypt at all on PHP 7.1 and higher. Instead, the kernel's CSPRNG is preferred.

  29. ramsey commented on Oct 5, 2017

    @ramsey
    Collaborator

    I have commit/merge access on this library, and I’ll be happy to review and merge in any PR to address this that doesn’t break BC.

  30. paragonie-scott commented on Oct 6, 2017

    @paragonie-scott

    @ramsey I may, after I get my fork stable, send a PR from a branch that undoes the BC breaks to review.

  31. Lauriy commented on Dec 11, 2017

    @Lauriy

    composer require paragonie/random-lib

    "replace": { "ircmaxell/random-lib":"*" },

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions