Repository navigation
AES-256-CBC-HMAC-SHA256 and similar ciphers are not recognized as authenticated ciphers #43040
Description
Activity
- addedconfirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.cryptoIssues and PRs related to the crypto subsystem.Issues and PRs related to the crypto subsystem.
on May 10, 2022 - removedconfirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.
on May 10, 2022 I am not sure if these algorithms ever worked as expected even when they weren't throwing exceptions, I'll add the label again once I've figured that out. Could you describe your use case for these algorithms?
I'm currently working on a project where I have to encrypt cookies using HMAC and AES. Of course I can use createHmac and separate the process, but these algorithms seem more convenient for me. I used the crypto.getCiphers function and found them and I was expecting them to work on the latest Node, but to my surprise this wasn't the case.
All in all not really breaking anything, but would be nice to have included I guess.
- addedopensslIssues and PRs related to the OpenSSL dependency.Issues and PRs related to the OpenSSL dependency.
on May 10, 2022 Looks like it's OpenSSL 3. Node.js versions using OpenSSL 1.1.1 do not throw.
Upon closer inspection, Node.js has never treated these algorithms as proper AEAD ciphers. In versions that do not throw when using them, they do not guarantee authenticity.
- changed the title
[-]Error: Trying to add data in unsupported state[/-][+]AES-256-CBC-HMAC-SHA256 and similar ciphers are not recognized as AEAD ciphers[/+]on May 10, 2022 - changed the title
[-]AES-256-CBC-HMAC-SHA256 and similar ciphers are not recognized as AEAD ciphers[/-][+]AES-256-CBC-HMAC-SHA256 and similar ciphers are not recognized as authenticated ciphers[/+]on May 10, 2022 - addedconfirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.
on May 10, 2022 they do not guarantee authenticity
Interesting discovery that you've made, let's hope it can be fixed
Arguably, OpenSSL is also treating these strangely. Maybe these ciphers mostly exist for TLS compatibility?
Can I ask if you are following some spec that demands using these ciphers?
I'm not following any spec. Just saw them and by their name I expected it to give me an HMAC hash alongside encrypting my data using AES, which is exactly what I was looking for.
I'm not following any spec. Just saw them and by their name I expected it to give me an HMAC hash alongside encrypting my data using AES, which is exactly what I was looking for.
@seirdotexe In that case, I'd strongly suggest AES-GCM instead. It's widely supported (even in client-side Web Crypto) and generally more efficient than AES-CBC + HMAC.
19 remaining items
- added a commit that references this issue
on Aug 25, 2026 - added a commit that references this issue
on Aug 25, 2026 - added 2 commits that reference this issue
on Aug 29, 2026 - added 2 commits that reference this issue
on Sep 15, 2026 - added 6 commits that reference this issue
on Sep 19, 2026 - added 2 commits that reference this issue
on Sep 21, 2026
Version
18.1.0
Platform
Microsoft Windows NT 10.0.19044.0 x64
Subsystem
crypto
What steps will reproduce the bug?
Run the following code:
How often does it reproduce? Is there a required condition?
This only reproduces when using:
What is the expected behavior?
On Node 17.1.0:
What do you see instead?
Additional information
It seems to work on LTS and above (tested until 17.1.0), but not on V18.