[horde] Horde update, not getting errors in log

John H. Bennett III bennettj at thebennetthome.com
Tue Nov 20 21:45:41 UTC 2012


Hello all,

Today I did a pear update, via pear upgrade -B -c horde, and now I see  
these errors when logging into the system.

Nov 20 12:13:08 www HORDE: [imp] PHP ERROR: openssl_encrypt() [<a  
href='function.openssl-encrypt'>function.openssl-encrypt</a>]: Using  
an empty Initialization Vector (iv) is potentially insecure and not  
recommended [pid 2919 on line 37 of  
"/usr/share/pear/Horde/Crypt/Blowfish/Openssl.php"]
Nov 20 12:13:08 www HORDE: [horde] PHP ERROR: openssl_encrypt() [<a  
href='function.openssl-encrypt'>function.openssl-encrypt</a>]: Using  
an empty Initialization Vector (iv) is potentially insecure and not  
recommended [pid 2919 on line 37 of  
"/usr/share/pear/Horde/Crypt/Blowfish/Openssl.php"]
Nov 20 12:13:08 www HORDE: [horde] Login success for  
admin at thehometest.com [10.10.10.125] to horde. [pid 2919 on line 163  
of "/home/httpd/html/horde/login.php"]
Nov 20 12:13:08 www HORDE: PHP ERROR: openssl_encrypt() [<a  
href='function.openssl-encrypt'>function.openssl-encrypt</a>]: Using  
an empty Initialization Vector (iv) is potentially insecure and not  
recommended [pid 2907 on line 37 of  
"/usr/share/pear/Horde/Crypt/Blowfish/Openssl.php"]
Nov 20 12:13:08 www HORDE: PHP ERROR: openssl_encrypt() [<a  
href='function.openssl-encrypt'>function.openssl-encrypt</a>]: Using  
an empty Initialization Vector (iv) is potentially insecure and not  
recommended [pid 2907 on line 37 of  
"/usr/share/pear/Horde/Crypt/Blowfish/Openssl.php"]
Nov 20 12:13:08 www HORDE: PHP ERROR: openssl_encrypt() [<a  
href='function.openssl-encrypt'>function.openssl-encrypt</a>]: Using  
an empty Initialization Vector (iv) is potentially insecure and not  
recommended [pid 2907 on line 37 of  
"/usr/share/pear/Horde/Crypt/Blowfish/Openssl.php"]
Nov 20 12:13:08 www HORDE: PHP ERROR: openssl_encrypt() [<a  
href='function.openssl-encrypt'>function.openssl-encrypt</a>]: Using  
an empty Initialization Vector (iv) is potentially insecure and not  
recommended [pid 2907 on line 37 of  
"/usr/share/pear/Horde/Crypt/Blowfish/Openssl.php"]
Nov 20 12:13:08 www HORDE: PHP ERROR: openssl_encrypt() [<a  
href='function.openssl-encrypt'>function.openssl-encrypt</a>]: Using  
an empty Initialization Vector (iv) is potentially insecure and not  
recommended [pid 2907 on line 37 of  
"/usr/share/pear/Horde/Crypt/Blowfish/Openssl.php"]
Nov 20 12:13:09 www HORDE: [imp] Login success for admin (Horde user  
admin at thehometest.com) [10.10.10.125] to {localhost:143 [imap]} [pid  
2907 on line 173 of "/home/httpd/html/horde/imp/lib/Auth.php"]
Nov 20 12:13:10 www HORDE: [kronolith] PHP ERROR: openssl_encrypt()  
[<a href='function.openssl-encrypt'>function.openssl-encrypt</a>]:  
Using an empty Initialization Vector (iv) is potentially insecure and  
not recommended [pid 2916 on line 37 of  
"/usr/share/pear/Horde/Crypt/Blowfish/Openssl.php"

I did a complete fresh install on my test server and I get the same errors.

Did I do something wrong on the upgrade, or install something I  
shouldn't have?  I've used the same method to update the system in the  
past, and things went fine.

Thanks,

John Bennett


-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: PGP Digital Signature
URL: <http://lists.horde.org/archives/horde/attachments/20121120/f63613ec/attachment.bin>


More information about the horde mailing list