I have just upgraded my Ubuntu system to 22.04 which comes with OpenSSL 3.0.2. Previously I was using 1.1.1f, and it seems the behavior has changed, but I'm not sure (1) why and (2) how to get the old behavior or what the new behavior is so I can adapt to it.
The issue is that I was expecting any openssl encrypted file to start with the bytes: "Salted__" or "U2FsdGVkX1" in Base64. I'm using that to determine if the file is encrypted or not.
If I use OpenSSL 3 with randomly generated salt things work fine.
echo "foo" >secret.txt
ENC_PASS=chbs openssl enc -aes-256-cbc -md sha256 -pass env:ENC_PASS -e -pbkdf2 -in secret.txt -a
Results in:
U2FsdGVkX1+BM+juJUWhy5eqBJ3k5BrrTs/V4l0QstA=
And I get a similar result with version 1.1.1f, but it's random so it's non deterministic.
However, in the application I'm working on, I need determinism, so I need to provide the salt. That's not a big deal openssl lets you do that with -S. On 1.1.1f I can do that and get:
ENC_PASS=chbs openssl enc -aes-256-cbc -md sha256 -pass env:ENC_PASS -e -S 5555555555555555 -pbkdf2 -in secret.txt -a
U2FsdGVkX19VVVVVVVVVVQkK+WIxriO4aZHXlxJOzDg=
This is deterministic, so you can use the same secret I did and get the same result.
But on 3.0.2 with the same command I get:
CQr5YjGuI7hpkdeXEk7MOA==
This is also deterministic, but why is it different? There doesn't seem to be a consistent pattern.
What happened? Did they stop prepending the salt to the message? Do I just have to manually add that bit if I want it? Is there anything I can do to get openssl to do that for me again? What was the reason for the change in behavior?