close

Filter

loading table of contents...

Deployment Manual / Version 2512.1

Table Of Contents

5.2.5 Using an RSA Key Pair from a Java Keystore

Instead of a shared symmetric key, the private key of an RSA key pair can be used for decryption. The public key is then sufficient for encryption, so the people or build jobs that encrypt a value never need access to the key that can decrypt it. This is the better choice whenever encryption and decryption happen in different places.

This variant needs one additional module on the classpath:

<dependency>
  <groupId>org.springframework.security</groupId>
  <artifactId>spring-security-rsa</artifactId>
</dependency>

Create the key pair with the JDK tool keytool:

keytool -genkeypair \
  -alias cmdemo \
  -keyalg RSA -keysize 2048 \
  -keystore encryption-demo.p12 -storetype pkcs12 \
  -storepass changeit -keypass changeit \
  -validity 36500 \
  -dname "CN=CoreMedia Documentation Demo, OU=Documentation, O=CoreMedia, C=DE"

Encrypt the value with the keystore. As in Section 5.2.2, “Encrypting a Value”, the program below uses the same API that the application uses for decryption. Build and run it in the same throwaway Maven project, which already declares spring-security-rsa for this purpose:

import org.springframework.cloud.bootstrap.encrypt.KeyProperties;
import org.springframework.cloud.bootstrap.encrypt.RsaProperties;
import org.springframework.cloud.bootstrap.encrypt.TextEncryptorUtils;
import org.springframework.core.io.FileSystemResource;
import org.springframework.security.crypto.encrypt.TextEncryptor;

public class EncryptWithKeyStore {
  public static void main(String[] args) {
    KeyProperties keyProperties = new KeyProperties();
    KeyProperties.KeyStore keyStore = keyProperties.getKeyStore();
    keyStore.setLocation(new FileSystemResource(args[0]));
    keyStore.setPassword(args[1]);
    keyStore.setAlias(args[2]);
    keyStore.setSecret(args[3]);
    TextEncryptor encryptor =
            TextEncryptorUtils.createTextEncryptor(keyProperties, new RsaProperties());
    System.out.println("{cipher}" + encryptor.encrypt(args[4]));
  }
}
java -cp "target/encrypt-tool-1.jar:$(cat classpath.txt)" EncryptWithKeyStore \
  encryption-demo.p12 "$KEYSTORE_PASSWORD" cmdemo "$KEY_SECRET" "$SECRET"

Configure the application with the following properties. As with encrypt.key, the keystore password and the key secret must come from outside the versioned configuration:

encrypt.key-store.location=file:/etc/coremedia/encryption-demo.p12
encrypt.key-store.type=pkcs12
encrypt.key-store.alias=cmdemo
encrypt.key-store.password=<keystore password>
encrypt.key-store.secret=<key password>

The property file itself looks exactly as in Section 5.2.3, “Writing the Property File”, and the failure behavior described there is the same. Note that encrypt.key-store.type defaults to jks and must therefore be set explicitly for a PKCS #12 keystore. The cipher text of this variant is Base64 encoded and considerably longer than the hexadecimal cipher text produced by the symmetric key.

Note

Note

spring-security-rsa is a small, separately released module whose published POM still declares dependencies of the Spring 5 generation. Those versions are overridden by the dependency management of a CoreMedia application, and the module has been verified to work on the Spring version shipped with this release. It also pulls in Bouncy Castle as a transitive dependency.

Search Results

Table Of Contents
warning

Your Internet Explorer is no longer supported.

Please use Mozilla Firefox, Google Chrome, or Microsoft Edge.