如何生成与OpenSSL C++ AES-256-CBC输出匹配的结果以编写单元测试?
Matching Your C++ AES-256-CBC Encryption with OpenSSL Command Line
First, let's align on the standard OpenSSL defaults your C++ wrapper is likely using (since you mentioned it follows OpenSSL docs):
- Padding: PKCS#7 (the default for OpenSSL AES-CBC; adds bytes to make input length a multiple of AES's 16-byte block size)
- Key size: 32 bytes (256 bits) for AES-256
- IV size: 16 bytes (128 bits, mandatory for CBC mode)
- Ciphertext output: Raw binary bytes (not Base64 encoded)
Step 1: Prepare Consistent Test Inputs
Pick sample values to test with—consistency here is key to matching outputs:
- Plaintext:
Hello, AES-256-CBC Test!(raw string, no trailing newline) - Key: 32-byte raw value (e.g., hex string
0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef, which decodes to 32 bytes) - IV: 16-byte raw value (e.g., hex string
abcdef1234567890abcdef1234567890, decodes to 16 bytes)
Step 2: OpenSSL Encryption Command (Raw Ciphertext Output)
If your wrapper accepts raw binary key/IV and outputs raw binary ciphertext, use this command to generate matching output:
echo -n "Hello, AES-256-CBC Test!" | openssl enc -aes-256-cbc -K 0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef -iv abcdef1234567890abcdef1234567890 -nosalt -out openssl_cipher.bin
Breakdown of critical flags:
-n: Preventsechofrom adding an extra trailing newline (this would change the plaintext length and break matching)-K: Passes the key as a hex string (OpenSSL decodes it to raw bytes automatically)-iv: Passes the IV as a hex string (same decoding logic)-nosalt: Disables salt (your wrapper likely doesn't use salt unless you explicitly added it—salt is optional and not part of basic AES-CBC)-out openssl_cipher.bin: Writes raw binary ciphertext to a file (you can compare this file's bytes directly with your wrapper's output)
Step 3: Verify Matching Outputs
To confirm the ciphertexts are identical:
- Save your C++ wrapper's encrypted bytes to a file (e.g.,
wrapper_cipher.bin) - Use the
cmpcommand to check for byte-for-byte equality:
cmp openssl_cipher.bin wrapper_cipher.bin
If there’s no output, the files are identical—success!
Step 4: Validate Decryption (Optional but Recommended)
To ensure both implementations can decrypt each other's output:
- Decrypt the OpenSSL-generated ciphertext with your wrapper: it should return the original plaintext
- Decrypt your wrapper's ciphertext with OpenSSL using this command:
cat wrapper_cipher.bin | openssl enc -aes-256-cbc -d -K 0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef -iv abcdef1234567890abcdef1234567890 -nosalt
This should print the exact original plaintext.
Common Troubleshooting for Mismatches
If outputs don’t align, check these common issues:
- Padding: Ensure your wrapper uses PKCS#7 padding (OpenSSL's default). If you’re using no padding, add
-nopadto the OpenSSL command. - Key/IV Length: AES-256 requires a 32-byte key; CBC requires a 16-byte IV. Double-check your wrapper isn’t truncating or padding these values incorrectly.
- Salt: If your wrapper uses salt (unlikely unless you added it), remove
-nosaltfrom the OpenSSL command and ensure your code handles the salt prepended to ciphertext (OpenSSL does this automatically when salt is enabled). - Endianness: Make sure your wrapper isn’t swapping byte order for key/IV—OpenSSL uses raw byte sequences, so as long as you pass the same byte order, it should work.
内容的提问来源于stack exchange,提问作者The Quantum Physicist
相关产品推荐
相关产品推荐

