yasithdev opened a new pull request, #610:
URL: https://github.com/apache/airavata/pull/610

   Extracted from #556. Upgrades credential store encryption from 
`AES/CBC/PKCS5Padding` with a **static zero IV** to `AES/GCM/NoPadding` with 
random IVs.
   
   ### What changed
   - `SecurityUtil`: New `encrypt(byte[], Key)` / `decrypt(byte[], Key)` API 
using GCM with 12-byte random IV prepended to ciphertext
   - `CredentialsDAO`: Updated to use new API (get key once, then 
encrypt/decrypt)
   - Removed old `encryptString`/`decryptString` methods that baked in keystore 
access
   
   ### Why
   - AES/CBC with static `new byte[16]` IV is insecure — identical plaintexts 
produce identical ciphertexts
   - GCM provides authenticated encryption (integrity + confidentiality)
   - Random IV per encryption ensures semantic security
   
   ### Migration note
   Existing encrypted credentials will need re-encryption. New credentials will 
use GCM format (12-byte IV prefix).
   
   All 9 modules build, all tests pass.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to