close

Filter

loading table of contents...

Deployment Manual / Version 2512.1

Table Of Contents

5.2.2 Encrypting a Value

Create the cipher text with the same key that the application will use at runtime. The following program uses the very API that the application uses for decryption, so the result is guaranteed to be readable by it:

import org.springframework.cloud.bootstrap.encrypt.KeyProperties;
import org.springframework.cloud.bootstrap.encrypt.RsaProperties;
import org.springframework.cloud.bootstrap.encrypt.TextEncryptorUtils;
import org.springframework.security.crypto.encrypt.TextEncryptor;

public class Encrypt {
  public static void main(String[] args) {
    KeyProperties keyProperties = new KeyProperties();
    keyProperties.setKey(args[0]);
    TextEncryptor encryptor =
            TextEncryptorUtils.createTextEncryptor(keyProperties, new RsaProperties());
    System.out.println("{cipher}" + encryptor.encrypt(args[1]));
  }
}

The program is not part of CoreMedia Content Cloud and is not shipped in any form, so you build it yourself. A throwaway Maven project with a single class and the following pom.xml is enough:

<project xmlns="http://maven.apache.org/POM/4.0.0">
  <modelVersion>4.0.0</modelVersion>
  <groupId>com.example</groupId>
  <artifactId>encrypt-tool</artifactId>
  <version>1</version>
  <properties>
    <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
    <maven.compiler.release>${java.specification.version}</maven.compiler.release>
    <!-- Use the versions of the CoreMedia release the encrypted values are meant for. -->
    <spring-cloud-context.version>...</spring-cloud-context.version>
    <spring-boot.version>...</spring-boot.version>
    <spring-security-rsa.version>...</spring-security-rsa.version>
  </properties>
  <dependencies>
    <dependency>
      <groupId>org.springframework.cloud</groupId>
      <artifactId>spring-cloud-context</artifactId>
      <version>${spring-cloud-context.version}</version>
    </dependency>
    <dependency>
      <groupId>org.springframework.boot</groupId>
      <artifactId>spring-boot</artifactId>
      <version>${spring-boot.version}</version>
    </dependency>
    <!-- Only required for the keystore variant. -->
    <dependency>
      <groupId>org.springframework.security</groupId>
      <artifactId>spring-security-rsa</artifactId>
      <version>${spring-security-rsa.version}</version>
    </dependency>
  </dependencies>
</project>
Important

Important

spring-boot has to be declared explicitly here, although the encryption tool is not a Spring Boot application. TextEncryptorUtils binds the key properties through Spring Boot's Binder, and spring-cloud-context does not pull that module in. Without it the tool fails with a NoClassDefFoundError for org.springframework.boot.context.properties.bind.BindHandler. Inside a CoreMedia Content Cloud application the module is present anyway, which is why Section 5.2.1, “Adding the Dependency” does not mention it. spring-security-crypto, in contrast, comes in transitively with spring-cloud-context and never has to be declared.

Build the project and collect the runtime classpath, then run the tool. Pass the key and the secret through environment variables so that they do not end up in the shell history:

mvn -q package dependency:build-classpath -Dmdep.outputFile=classpath.txt

java -cp "target/encrypt-tool-1.jar:$(cat classpath.txt)" Encrypt "$ENCRYPT_KEY" "$SECRET"

Run the encryption on a trusted machine only. The clear text secret and the key are both present in the process and are therefore visible to anyone who can read the process list of that machine.

Search Results

Table Of Contents
warning

Your Internet Explorer is no longer supported.

Please use Mozilla Firefox, Google Chrome, or Microsoft Edge.