A table in my database has some fields that need to be encrypted. I would like to use php functions openssl_encrypt and openssl_decrypt to write and read data in my php webapp.
A key, an initialization vector and a tag are used to encrypt and decrypt the data.
iv and tags should always be different every time data is encrypted.
My question is, how should key, iv and tags be stored properly?
on the database? in the webapp? in an external file?
what security measures should i take?
thanks!