I am developing an application where encryption is required to communicate with server side. I have also implemented that and running okay with my web application (WAR) on Jboss AS 7.1. But another standalone application (JAR) is there which also needs that same kind of encryption and I implemented that same code customized for that standalone version. But it is not working and showing below error - (I am using Jdk version : jdk1.7.0_80, O/S: Windows 10)
Error while encrypting: java.security.InvalidKeyException: Illegal key size
java.security.InvalidKeyException: Illegal key size
at javax.crypto.Cipher.checkCryptoPerm(Cipher.java:1029)
at javax.crypto.Cipher.implInit(Cipher.java:795)
at javax.crypto.Cipher.chooseProvider(Cipher.java:854)
at javax.crypto.Cipher.init(Cipher.java:1374)
at javax.crypto.Cipher.init(Cipher.java:1308)
at in.issac.lib.EncryptUtil.doEncrypt(EncryptUtil.java:44)
From several posts I got the idea that, we can remove the maximum key restriction by replacing the existing JCE jars with unlimited strength policy jars.
For JAVA 7 the download link is jce-7-download (Link is directed to Oracle download site)
Copy local_policy.jar and US_export_policy.jar extracted from above zip file to the $JAVA_HOME/jre/lib/security
I did exactly same and after that my web application started doing the encryption correctly. But still my standalone JAR is NOT working. It is showing the same error.
I am sharing my encryption code here below : Encryption :
try
{
MessageDigest md = MessageDigest.getInstance("SHA-256");
byte[] digestOfPassword = md.digest(passedKey.getBytes("UTF-8"));
byte[] keyBytes =Arrays.copyOf(digestOfPassword, 24);
byte[] iv = Arrays.copyOf(digestOfPassword, 16);
SecretKey key = new SecretKeySpec(keyBytes, "AES");
Cipher cipher = Cipher.getInstance("AES/CBC/PKCS5Padding");
IvParameterSpec IvParameterSpec = new IvParameterSpec(iv);
cipher.init(Cipher.ENCRYPT_MODE, key, IvParameterSpec);
byte[] plainTextBytes = strValue.getBytes("UTF-8");
byte[] buf = cipher.doFinal(plainTextBytes);
byte[] base64Bytes = Base64.encode(buf).getBytes();
base64EncryptedString = new String(base64Bytes);
}
catch (Exception e)
{
System.out.println("Error while encrypting: " + e.toString());
e.printStackTrace();
}
Can anyone help me, how can I get rid off such error for my Java standalone application ?