Andrea Cosentino created CAMEL-24506:
----------------------------------------

             Summary: camel-jasypt-starter - modernise the default algorithm 
and fix the usage example's password placement
                 Key: CAMEL-24506
                 URL: https://issues.apache.org/jira/browse/CAMEL-24506
             Project: Camel
          Issue Type: Improvement
          Components: camel-jasypt, camel-spring-boot-starters
            Reporter: Andrea Cosentino
            Assignee: Andrea Cosentino


Two items in the same starter, distinct root causes.

*1. Default algorithm*

{code:java}
/**
 * The algorithm to be used for decryption. Default: PBEWithMD5AndDES
 */
private String algorithm = "PBEWithMD5AndDES";
{code}

(JasyptEncryptedPropertiesConfiguration:42)

{{PBEWithMD5AndDES}} is a 56-bit DES cipher with an MD5-based key derivation. 
The starter already carries {{PBEWITHHMACSHA256ANDAES_256}} in its 
{{ALGORITHMS_THAT_REQUIRE_IV}} set, so the {{RandomIvGenerator}} path engages 
automatically if it becomes the default.

Changing the default is a breaking change for values encrypted under the old 
one, so it needs an upgrade-guide entry and an explicit opt-back 
({{camel.component.jasypt.algorithm=PBEWithMD5AndDES}}), and should be 
coordinated with the upstream camel-jasypt component default rather than 
diverging from it.

*2. Usage example places the master password beside the ciphertext*

{code:properties}
my.secret = ENC(encrypted-value-here)
camel.component.jasypt.password = the-master-password
{code}

(src/main/doc/usage.adoc:6)

The example puts the decryption key in the same file as the encrypted value, 
which removes the benefit of encrypting it. The starter already supports 
{{sysenv:}} and {{sys:}} prefixes for exactly this, and {{jasypt.json}} 
documents them.

*Proposal*: change the example to {{camel.component.jasypt.password = 
sysenv:JASYPT_PASSWORD}} and add a sentence stating the master password must 
come from the environment or an external secret store and must not live 
alongside the encrypted values.

----
_This issue was drafted by Claude Code on behalf of Andrea Cosentino._



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to