yasithdev opened a new pull request, #610: URL: https://github.com/apache/airavata/pull/610
Extracted from #556. Upgrades credential store encryption from `AES/CBC/PKCS5Padding` with a **static zero IV** to `AES/GCM/NoPadding` with random IVs. ### What changed - `SecurityUtil`: New `encrypt(byte[], Key)` / `decrypt(byte[], Key)` API using GCM with 12-byte random IV prepended to ciphertext - `CredentialsDAO`: Updated to use new API (get key once, then encrypt/decrypt) - Removed old `encryptString`/`decryptString` methods that baked in keystore access ### Why - AES/CBC with static `new byte[16]` IV is insecure — identical plaintexts produce identical ciphertexts - GCM provides authenticated encryption (integrity + confidentiality) - Random IV per encryption ensures semantic security ### Migration note Existing encrypted credentials will need re-encryption. New credentials will use GCM format (12-byte IV prefix). All 9 modules build, all tests pass. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
