[ 
https://issues.apache.org/jira/browse/NIFI-1242?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15042317#comment-15042317
 ] 

Joseph Witt commented on NIFI-1242:
-----------------------------------

+1.

Full clean build all good.  Code review is favorable.  Commented on suggested 
doc improvement.  Functional test that definitely did not work before is now 
awesome and things that worked before still seem to work.

Very nicely done and great to have someone digging into this.

> Password-based encryption is not compatible with OpenSSL
> --------------------------------------------------------
>
>                 Key: NIFI-1242
>                 URL: https://issues.apache.org/jira/browse/NIFI-1242
>             Project: Apache NiFi
>          Issue Type: Bug
>          Components: Extensions
>    Affects Versions: 0.4.0
>            Reporter: Andy LoPresto
>            Assignee: Andy LoPresto
>            Priority: Critical
>              Labels: security
>             Fix For: 0.4.0
>
>         Attachments: Decrypt_Alter_Encrypt_OpenSSL.xml, NIFI-1242.0001.patch
>
>   Original Estimate: 24h
>  Remaining Estimate: 24h
>
> Despite the algorithm names indicating compatibility with OpenSSL, the 
> current password-based encryption processors cannot decrypt data that was 
> encrypted with OpenSSL external to NiFi. 
> I will create a new OpenSSLPBEEncryptor implementation, a new 
> EncryptionMethod, and wire the logic in EncryptContent to select the correct 
> encryptor. 
> I have a more in-depth explanation of the issue at 
> https://github.com/alopresto/opensslpbeencryptor/blob/master/blog.md, but the 
> fix is done in a sandbox and will be moved into NiFi by morning 12/03/15. 



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to