Programming Tutorials

Encrypting files using GnuPG (GPG) via PHP

By: Darrell Brogdon in PHP Tutorials on 2011-01-24  

Quite often your PHP scripts are written to run automatically within the web server without any intervention by you. What kind of life can you expect to lead if you have to enter your GnuPG passphrase every time PHP tries to decrypt a file? But we're getting a little ahead of ourselves. Let's first look at how we can encrypt a file with GnuPG and PHP.

The following script does just that:

<?php 
$gpg = '/usr/bin/gpg';
$recipient = '[email protected]';
$secret_file = 'secret_file.txt'; echo shell_exec("$gpg -e -r $recipient $secret_file");
?>

After running this script you will find 'secret_file.txt.gpg' in your directory (Again, make sure '[email protected]' is in your public key ring!). This is assuming that GnuPG generated no errors. If it did then they will be echoed to STDOUT.

From here there are several things you can do. For one, if there are any errors you probably want to look for them within the script instead of just echoing them for the entire world to see. You might also want to email the encrypted file to Mr. Doe using PHP's mail()command.

But what if you want to encrypt raw data not contained in a file? This too is possible by piping the data directly to GnuPG:

<?php 
$gpg = '/usr/bin/gpg';
$recipient = '[email protected]';
$encrypted_file = 'foo.gpg';
shell_exec("echo $argv[1] | $gpg -e -r $recipient -o $encrypted_file");
?>

This script takes the value of $argv[1], the first argument after the script name, and passes it to GnuPG for encrypting. GnuPG, using the -oswitch, writes the encrypted data out to $encrypted_file. Again, you will probably want to check for and deal with any errors generated by GnuPG.

Another option is to leave off the -o $encrypted_filepart and store the encrypted data inside a variable. That way you can use PHP to do with the encrypted data as you please, saving valuable file I/O.

<?php 
$gpg = '/usr/bin/gpg';
$recipient = '[email protected]';
$encrypted_message = base64_encode(shell_exec("echo $argv[1] | $gpg -e -r $recipient"));
mail('[email protected]',
'Your Encrypted Message',
$enrypted_message);
?>

If you do this is especially important that you Base-64 encode the data so you can play nice with the email client receiving the encrypted message.






Add Comment

* Required information
1000

Comments

No comments yet. Be the first!

Most Viewed Articles (in PHP )

All possible substrings in a String in PHP

Comparison operators in PHP

Iterating Through an Array in PHP

Multiple File Upload in PHP using IFRAME

Building a Video Sharing Site using PHP in AWS

Encrypting files using GnuPG (GPG) via PHP

PHP pages does not display in IIS 6 with Windows 2003

Installing PHP with Apache 2.x on HP UX 11i and configuring PHP with Oracle 9i

Cannot load /usr/local/apache/libexec/libphp4.so into server: ld.so.1:......

Setting up PHP in Windows 2003 Server IIS7, and WinXP 64

error: "Service Unavailable" after installing PHP to a Windows XP x64 Pro

Running different websites on different versions of PHP in Windows 2003 & IIS6 platform

Installing PHP with nginx-server under windows

Function to return number of digits of an integer in PHP

Function to sort array by elements and count of element in PHP

Latest Articles (in PHP)