Use asymmetric key as PEM-encoded text on spring cloud config server

Viewed 296

I created a config-server based on this github example: https://github.com/spring-cloud-samples/configserver

I changed it in order to point to my local git repository and also installed the full-strength JCE installed in my environment.

The encryption and decryption features worked as expected using an asymmetric key with the keystore jks file: created an encrypted value using the /encrypt endpoint; included it into my git repo (test property); get the key decrypted from the /{app}-{env}.yml endpoint.

The spring cloud config docs says that it's possible to set the asymmetric key as PEM-encoded text value in encrypt.key: http://cloud.spring.io/spring-cloud-config/1.4.x/single/spring-cloud-config.html#_key_management

I converted the keystore.jks file into a PEM file with the following:

  1. keytool -importkeystore -srckeystore keystore.jks -destkeystore key.p12 -srcalias test -srcstoretype jks -deststoretype pkcs12

  2. openssl pkcs12 -in key.p12 -out key.pem

I changed the bootstrap.yml file and included the contents of the key.pem file:

encrypt:
  failOnError: false
  key: |
    Bag Attributes
        friendlyName: test
        localKeyID: 54 69 6D 65 20 31 35 33 37 32 31 39 34 35 38 32 30 31 
    Key Attributes: <No Attributes>
    -----BEGIN ENCRYPTED PRIVATE KEY-----
    MIIFDjBABgkqhkiG9w0BBQ0wMzAbBgkqhkiG9w0BBQwwDgQIFxcOg3aNibsCAggA
    (...)
    0m6f+FvV3glvSE4C86VeNwKUdiEMKtzf5A/Ie9B0jhjIP/R0n4tSuQNNNRfetJxB
    3mk=
    -----END ENCRYPTED PRIVATE KEY-----
    Bag Attributes
        friendlyName: test
        localKeyID: 54 69 6D 65 20 31 35 33 37 32 31 39 34 35 38 32 30 31 
    subject=/C=Unknown/ST=Unknown/L=Unknown/O=Unknown/OU=Unknown/CN=Unknown
    issuer=/C=Unknown/ST=Unknown/L=Unknown/O=Unknown/OU=Unknown/CN=Unknown
    -----BEGIN CERTIFICATE-----
    MIIDdzCC
    (...)
    aMgI8QW+kQ
    -----END CERTIFICATE-----

And now it fails to decrypt the test property with the error:

Cannot decrypt key: sftp.privateKeyPassphrase (class java.lang.IllegalArgumentException: Non-hex character in input: ..)

  1. Is that supposed to work as I expected or do I need to regenerate the encrypted value?
  2. If the latter is true, isn't my key being used as a symmetric key instead?
  3. I would like to avoid using configuration files and have all set with environment variables. Is there any other possibility?
0 Answers
Related