I created a config-server based on this github example: https://github.com/spring-cloud-samples/configserver
I changed it in order to point to my local git repository and also installed the full-strength JCE installed in my environment.
The encryption and decryption features worked as expected using an asymmetric key with the keystore jks file: created an encrypted value using the /encrypt endpoint; included it into my git repo (test property); get the key decrypted from the /{app}-{env}.yml endpoint.
The spring cloud config docs says that it's possible to set the asymmetric key as PEM-encoded text value in encrypt.key:
http://cloud.spring.io/spring-cloud-config/1.4.x/single/spring-cloud-config.html#_key_management
I converted the keystore.jks file into a PEM file with the following:
keytool -importkeystore -srckeystore keystore.jks -destkeystore key.p12 -srcalias test -srcstoretype jks -deststoretype pkcs12openssl pkcs12 -in key.p12 -out key.pem
I changed the bootstrap.yml file and included the contents of the key.pem file:
encrypt:
failOnError: false
key: |
Bag Attributes
friendlyName: test
localKeyID: 54 69 6D 65 20 31 35 33 37 32 31 39 34 35 38 32 30 31
Key Attributes: <No Attributes>
-----BEGIN ENCRYPTED PRIVATE KEY-----
MIIFDjBABgkqhkiG9w0BBQ0wMzAbBgkqhkiG9w0BBQwwDgQIFxcOg3aNibsCAggA
(...)
0m6f+FvV3glvSE4C86VeNwKUdiEMKtzf5A/Ie9B0jhjIP/R0n4tSuQNNNRfetJxB
3mk=
-----END ENCRYPTED PRIVATE KEY-----
Bag Attributes
friendlyName: test
localKeyID: 54 69 6D 65 20 31 35 33 37 32 31 39 34 35 38 32 30 31
subject=/C=Unknown/ST=Unknown/L=Unknown/O=Unknown/OU=Unknown/CN=Unknown
issuer=/C=Unknown/ST=Unknown/L=Unknown/O=Unknown/OU=Unknown/CN=Unknown
-----BEGIN CERTIFICATE-----
MIIDdzCC
(...)
aMgI8QW+kQ
-----END CERTIFICATE-----
And now it fails to decrypt the test property with the error:
Cannot decrypt key: sftp.privateKeyPassphrase (class java.lang.IllegalArgumentException: Non-hex character in input: ..)
- Is that supposed to work as I expected or do I need to regenerate the encrypted value?
- If the latter is true, isn't my key being used as a symmetric key instead?
- I would like to avoid using configuration files and have all set with environment variables. Is there any other possibility?