Merge branch '1.3.x'

This commit is contained in:
Spencer Gibb
2018-03-21 10:40:11 -04:00
5 changed files with 180 additions and 71 deletions

View File

@@ -41,7 +41,7 @@ import org.springframework.util.StringUtils;
*/
@Configuration
@ConditionalOnClass({ TextEncryptor.class })
@EnableConfigurationProperties(KeyProperties.class)
@EnableConfigurationProperties({KeyProperties.class})
public class EncryptionBootstrapConfiguration {
@Autowired(required = false)
@@ -53,11 +53,15 @@ public class EncryptionBootstrapConfiguration {
@Configuration
@Conditional(KeyCondition.class)
@ConditionalOnClass(RsaSecretEncryptor.class)
@EnableConfigurationProperties({RsaProperties.class})
protected static class RsaEncryptionConfiguration {
@Autowired
private KeyProperties key;
@Autowired
private RsaProperties rsaProperties;
@Bean
@ConditionalOnMissingBean(TextEncryptor.class)
public TextEncryptor textEncryptor() {
@@ -69,10 +73,10 @@ public class EncryptionBootstrapConfiguration {
keyStore.getPassword().toCharArray()).getKeyPair(
keyStore.getAlias(),
keyStore.getSecret().toCharArray()),
this.key.getRsa().getAlgorithm(), this.key.getRsa().getSalt(),
this.key.getRsa().isStrong());
}
this.rsaProperties.getAlgorithm(), this.rsaProperties.getSalt(),
this.rsaProperties.isStrong());
}
throw new IllegalStateException("Invalid keystore location");
}

View File

@@ -17,8 +17,6 @@ package org.springframework.cloud.bootstrap.encrypt;
import org.springframework.boot.context.properties.ConfigurationProperties;
import org.springframework.core.io.Resource;
import org.springframework.security.rsa.crypto.RsaAlgorithm;
import org.springframework.util.ClassUtils;
@ConfigurationProperties("encrypt")
public class KeyProperties {
@@ -46,22 +44,6 @@ public class KeyProperties {
*/
private KeyStore keyStore = new KeyStore();
/**
* Rsa algorithm properties when using asymmetric encryption.
*/
private Rsa rsa;
{
if (ClassUtils.isPresent("org.springframework.security.rsa.crypto.RsaAlgorithm",
null)) {
this.rsa = new Rsa();
}
}
public Rsa getRsa() {
return this.rsa;
}
public boolean isFailOnError() {
return this.failOnError;
}
@@ -149,52 +131,4 @@ public class KeyProperties {
}
}
public static class Rsa {
/**
* The RSA algorithm to use (DEFAULT or OAEP). Once it is set do not change it (or
* existing ciphers will not a decryptable).
*/
private RsaAlgorithm algorithm = RsaAlgorithm.OAEP;
/**
* Flag to indicate that "strong" AES encryption should be used internally. If
* true then the GCM algorithm is applied to the AES encrypted bytes. If false
* then the "standard" CBC is used instead. Once it is set do not change it (or
* existing ciphers will not a decryptable).
*/
private boolean strong = true;
/**
* Salt for the random secret used to encrypt cipher text. Once it is set do not
* change it (or existing ciphers will not a decryptable).
*/
private String salt = "deadbeef";
public RsaAlgorithm getAlgorithm() {
return this.algorithm;
}
public void setAlgorithm(RsaAlgorithm algorithm) {
this.algorithm = algorithm;
}
public boolean isStrong() {
return this.strong;
}
public void setStrong(boolean strong) {
this.strong = strong;
}
public String getSalt() {
return this.salt;
}
public void setSalt(String salt) {
this.salt = salt;
}
}
}

View File

@@ -0,0 +1,73 @@
package org.springframework.cloud.bootstrap.encrypt;
/*
* Copyright 2013-2018 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
import org.springframework.boot.autoconfigure.condition.ConditionalOnClass;
import org.springframework.boot.context.properties.ConfigurationProperties;
import org.springframework.security.rsa.crypto.RsaAlgorithm;
/**
* @author Ryan Baxter
*/
@ConditionalOnClass(RsaAlgorithm.class)
@ConfigurationProperties("encrypt.rsa")
public class RsaProperties {
/**
* The RSA algorithm to use (DEFAULT or OEAP). Once it is set do not change it (or
* existing ciphers will not a decryptable).
*/
private RsaAlgorithm algorithm = RsaAlgorithm.DEFAULT;
/**
* Flag to indicate that "strong" AES encryption should be used internally. If
* true then the GCM algorithm is applied to the AES encrypted bytes. Default is
* false (in which case "standard" CBC is used instead). Once it is set do not
* change it (or existing ciphers will not a decryptable).
*/
private boolean strong = false;
/**
* Salt for the random secret used to encrypt cipher text. Once it is set do not
* change it (or existing ciphers will not a decryptable).
*/
private String salt = "deadbeef";
public RsaAlgorithm getAlgorithm() {
return this.algorithm;
}
public void setAlgorithm(RsaAlgorithm algorithm) {
this.algorithm = algorithm;
}
public boolean isStrong() {
return this.strong;
}
public void setStrong(boolean strong) {
this.strong = strong;
}
public String getSalt() {
return this.salt;
}
public void setSalt(String salt) {
this.salt = salt;
}
}

View File

@@ -1,14 +1,32 @@
package org.springframework.cloud.bootstrap.encrypt;
/*
* Copyright 2013-2018 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
import org.junit.Test;
import org.springframework.boot.WebApplicationType;
import org.springframework.boot.builder.SpringApplicationBuilder;
import org.springframework.context.ConfigurableApplicationContext;
import org.springframework.security.crypto.encrypt.TextEncryptor;
import org.springframework.security.rsa.crypto.RsaAlgorithm;
import static org.assertj.core.api.Assertions.assertThat;
import static org.junit.Assert.assertEquals;
import static org.junit.Assert.assertTrue;
public class EncryptionBootstrapConfigurationTests {
@@ -52,6 +70,25 @@ public class EncryptionBootstrapConfigurationTests {
context.close();
}
@Test
public void rsaProperties() {
ConfigurableApplicationContext context = new SpringApplicationBuilder(
EncryptionBootstrapConfiguration.class).web(false).properties(
"encrypt.key-store.location:classpath:/server.jks",
"encrypt.key-store.password:letmein",
"encrypt.key-store.alias:mytestkey", "encrypt.key-store.secret:changeme",
"encrypt.rsa.strong:true",
"encrypt.rsa.salt:foobar")
.run();
RsaProperties properties = context.getBean(RsaProperties.class);
assertEquals("foobar", properties.getSalt());
assertTrue(properties.isStrong());
assertEquals(RsaAlgorithm.DEFAULT, properties.getAlgorithm());
context.close();
}
@Test
public void nonExistentKeystoreLocationShouldNotBeAllowed() {
try {

View File

@@ -0,0 +1,61 @@
package org.springframework.cloud.bootstrap.encrypt;
/*
* Copyright 2013-2018 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
import java.util.Map;
import org.junit.After;
import org.junit.Before;
import org.junit.Test;
import org.junit.runner.RunWith;
import org.springframework.boot.builder.SpringApplicationBuilder;
import org.springframework.cloud.ClassPathExclusions;
import org.springframework.cloud.FilteredClassPathRunner;
import org.springframework.context.ConfigurableApplicationContext;
import static org.hamcrest.MatcherAssert.assertThat;
import static org.hamcrest.Matchers.hasSize;
/**
* @author Ryan Baxter
*/
@RunWith(FilteredClassPathRunner.class)
@ClassPathExclusions({"spring-security-rsa*.jar"})
public class RsaDisabledTests {
private ConfigurableApplicationContext context;
@Before
public void setUp() {
context = new SpringApplicationBuilder().web(false)
.sources(EncryptionBootstrapConfiguration.class).web(false).properties(
"encrypt.key:mykey",
"encrypt.rsa.strong:true",
"encrypt.rsa.salt:foobar").run();
}
@After
public void tearDown() {
if(context != null) {
context.close();
}
}
@Test
public void testLoadBalancedRetryFactoryBean() throws Exception {
Map<String, RsaProperties> properties = context.getBeansOfType(RsaProperties.class);
assertThat(properties.values(), hasSize(0));
}
}