Deployment Manual / Version 2512.1
Table Of ContentsCreate the cipher text with the same key that the application will use at runtime. The following program uses the very API that the application uses for decryption, so the result is guaranteed to be readable by it:
import org.springframework.cloud.bootstrap.encrypt.KeyProperties;
import org.springframework.cloud.bootstrap.encrypt.RsaProperties;
import org.springframework.cloud.bootstrap.encrypt.TextEncryptorUtils;
import org.springframework.security.crypto.encrypt.TextEncryptor;
public class Encrypt {
public static void main(String[] args) {
KeyProperties keyProperties = new KeyProperties();
keyProperties.setKey(args[0]);
TextEncryptor encryptor =
TextEncryptorUtils.createTextEncryptor(keyProperties, new RsaProperties());
System.out.println("{cipher}" + encryptor.encrypt(args[1]));
}
}
The program is not part of CoreMedia Content Cloud and is not shipped in any form, so you build it
yourself. A throwaway Maven project with a single class and the following
pom.xml is enough:
<project xmlns="http://maven.apache.org/POM/4.0.0"> <modelVersion>4.0.0</modelVersion> <groupId>com.example</groupId> <artifactId>encrypt-tool</artifactId> <version>1</version> <properties> <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding> <maven.compiler.release>${java.specification.version}</maven.compiler.release> <!-- Use the versions of the CoreMedia release the encrypted values are meant for. --> <spring-cloud-context.version>...</spring-cloud-context.version> <spring-boot.version>...</spring-boot.version> <spring-security-rsa.version>...</spring-security-rsa.version> </properties> <dependencies> <dependency> <groupId>org.springframework.cloud</groupId> <artifactId>spring-cloud-context</artifactId> <version>${spring-cloud-context.version}</version> </dependency> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot</artifactId> <version>${spring-boot.version}</version> </dependency> <!-- Only required for the keystore variant. --> <dependency> <groupId>org.springframework.security</groupId> <artifactId>spring-security-rsa</artifactId> <version>${spring-security-rsa.version}</version> </dependency> </dependencies> </project>
Important
spring-boot has to be declared explicitly here, although the encryption
tool is not a Spring Boot application.
TextEncryptorUtils binds the key properties through Spring Boot's
Binder, and spring-cloud-context does not pull
that module in. Without it the tool fails with a
NoClassDefFoundError for
org.springframework.boot.context.properties.bind.BindHandler.
Inside a CoreMedia Content Cloud application the module is present anyway, which is why
Section 5.2.1, “Adding the Dependency” does not mention it.
spring-security-crypto, in contrast, comes in transitively with
spring-cloud-context and never has to be declared.
Build the project and collect the runtime classpath, then run the tool. Pass the key and the secret through environment variables so that they do not end up in the shell history:
mvn -q package dependency:build-classpath -Dmdep.outputFile=classpath.txt java -cp "target/encrypt-tool-1.jar:$(cat classpath.txt)" Encrypt "$ENCRYPT_KEY" "$SECRET"
Run the encryption on a trusted machine only. The clear text secret and the key are both present in the process and are therefore visible to anyone who can read the process list of that machine.


