Failure with DECRYPT_CHAR
Posted in 2011
Topics: Security, Permissions & Auditing, Platform-Specific Issues, Versions, Editions & End-of-Life
Version 11.50.FC7, HP-UX 11.31 ia64 I have run into a strange problem. I have two databases in the same instance. I encrypt a column with ENCRYPT_AES in one of these and decrypt it using DECRYPT_CHAR, no problem at all. In the exact same table in the other database I do the ENCRYPT_AES, this works OK, but when I try to decrypt I get -26012 The internal base64 decoding function failed. The internal crypto library base64 decoding API failed. it may be caused by a corrupted data. I have so far failed to understand this, I use the same SP to do the encryption and the same to do the decryption, any idea to why I get this error in the second database. The data that I encrypt is the same. Ulf
On Wed, May 4, 2011 at 04:53, Ulf <ulf.akerberg@gmail.com> wrote: > Version 11.50.FC7, HP-UX 11.31 ia64 > > I have run into a strange problem. I have two databases in the same > instance. I encrypt a column with ENCRYPT_AES in one of these and > decrypt it using DECRYPT_CHAR, no problem at all. > > In the exact same table in the other database I do the ENCRYPT_AES, > this works OK, but when I try to decrypt I get > > > -26012 The internal base64 decoding function failed. > > The internal crypto library base64 decoding API failed. > it may be caused by a corrupted data. > > I have so far failed to understand this, I use the same SP to do the > encryption and the same to do the decryption, any idea to why I get > this error in the second database. The data that I encrypt is the > same. > Are you quite sure that both tables have exactly the same lengths for the encrypted column? Can you see any length difference between the two encrypted (base-64 encoded) values? There should be nothing to recognize from the base-64 encodings - they are encrypted first - but the lengths should be the same. What was the length of the data that was encrypted? What is the length of the column you are storing it in? -- Jonathan Leffler <jonathan.leffler@gmail.com> #include <disclaimer.h> Guardian of DBD::Informix - v2008.0513 - http://dbi.perl.org "Blessed are we who can laugh at ourselves, for we shall never cease to be amused."
Thanks Jonathan ! The problem was indeed the length of the column (and the way I tested). I increased the length of the encrypted column, ran a "select length (encrypted column)" and found that for some data the original column length was insufficient. It is a bit surprising how much more space that is required, in this case a 20 char unencrypted column requires 67 characters encrypted.