Deployment Manual / Version 2512.1
Table Of ContentsInstead of a shared symmetric key, the private key of an RSA key pair can be used for decryption. The public key is then sufficient for encryption, so the people or build jobs that encrypt a value never need access to the key that can decrypt it. This is the better choice whenever encryption and decryption happen in different places.
This variant needs one additional module on the classpath:
<dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-rsa</artifactId> </dependency>
Create the key pair with the JDK tool keytool:
keytool -genkeypair \ -alias cmdemo \ -keyalg RSA -keysize 2048 \ -keystore encryption-demo.p12 -storetype pkcs12 \ -storepass changeit -keypass changeit \ -validity 36500 \ -dname "CN=CoreMedia Documentation Demo, OU=Documentation, O=CoreMedia, C=DE"
Encrypt the value with the keystore. As in
Section 5.2.2, “Encrypting a Value”, the program below uses the same API that
the application uses for decryption. Build and run it in the same throwaway Maven project,
which already declares spring-security-rsa for this purpose:
import org.springframework.cloud.bootstrap.encrypt.KeyProperties;
import org.springframework.cloud.bootstrap.encrypt.RsaProperties;
import org.springframework.cloud.bootstrap.encrypt.TextEncryptorUtils;
import org.springframework.core.io.FileSystemResource;
import org.springframework.security.crypto.encrypt.TextEncryptor;
public class EncryptWithKeyStore {
public static void main(String[] args) {
KeyProperties keyProperties = new KeyProperties();
KeyProperties.KeyStore keyStore = keyProperties.getKeyStore();
keyStore.setLocation(new FileSystemResource(args[0]));
keyStore.setPassword(args[1]);
keyStore.setAlias(args[2]);
keyStore.setSecret(args[3]);
TextEncryptor encryptor =
TextEncryptorUtils.createTextEncryptor(keyProperties, new RsaProperties());
System.out.println("{cipher}" + encryptor.encrypt(args[4]));
}
}java -cp "target/encrypt-tool-1.jar:$(cat classpath.txt)" EncryptWithKeyStore \ encryption-demo.p12 "$KEYSTORE_PASSWORD" cmdemo "$KEY_SECRET" "$SECRET"
Configure the application with the following properties. As with
encrypt.key, the keystore password and the key secret must come from
outside the versioned configuration:
encrypt.key-store.location=file:/etc/coremedia/encryption-demo.p12 encrypt.key-store.type=pkcs12 encrypt.key-store.alias=cmdemo encrypt.key-store.password=<keystore password> encrypt.key-store.secret=<key password>
The property file itself looks exactly as in
Section 5.2.3, “Writing the Property File”, and the failure behavior described there
is the same. Note that encrypt.key-store.type defaults to
jks and must therefore be set explicitly for a PKCS #12 keystore. The cipher
text of this variant is Base64 encoded and considerably longer than the hexadecimal cipher
text produced by the symmetric key.
Note
spring-security-rsa is a small, separately released module whose
published POM still declares dependencies of the Spring 5 generation. Those versions are
overridden by the dependency management of a CoreMedia application, and the module has
been verified to work on the Spring version shipped with this release. It also pulls in
Bouncy Castle as a transitive dependency.


