close

Filter

loading table of contents...

Deployment Manual / Version 2512.1

Table Of Contents

5.2.6 Limitations and Operational Notes

  • Startup fails on an undecryptable value. If the key is missing or wrong, the application does not start and reports Cannot decrypt: key=<property name>. The message names the affected property but never its value. This is the desired behavior: without it, the cipher text itself would be passed on as if it were the password. Do not set encrypt.fail-on-error to false in production.

  • No key rotation. There is no mechanism to roll over to a new key. Rotating it means re-encrypting every value with the new key and redeploying the configuration.

  • Per-application setup. Both the dependency and the key have to be added to every application that reads encrypted properties.

  • Do not mix it with the encryption service. This mechanism is unrelated to Chapter 4, Encryption Service Setup. It decrypts values in the Spring environment, whereas the encryption service decrypts the specific secrets that CoreMedia Content Cloud manages. Using both for the same value is not supported.

Search Results

Table Of Contents
warning

Your Internet Explorer is no longer supported.

Please use Mozilla Firefox, Google Chrome, or Microsoft Edge.