[ 
https://issues.apache.org/jira/browse/NIFI-16409?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18121641#comment-18121641
 ] 

ASF subversion and git services commented on NIFI-16409:
--------------------------------------------------------

Commit 3a363bbb7c6bf7b1f9ac78be3961168d46329e5c in nifi's branch 
refs/heads/main from David Handermann
[ https://gitbox.apache.org/repos/asf?p=nifi.git;h=3a363bbb7c6 ]

NIFI-16409 Replace Bouncy Castle with JDK in StandardPrivateKeyService (#11744)

* NIFI-16409 Replaced Bouncy Castle with JDK in StandardPrivateKeyService

- Added StandardPrivateKeyReader with supported PEM formats limited to PKCS8
- Added minimal DerElement parsing for reading Object Identifiers
- Restricted Cipher Algorithm support to AES and 3DES
- Removed undocumented support for PKCS1 and legacy OpenSSL encryption
- Expanded Capability Description to highlight focus on PBES2 and lack of 
guarantees for PBES1

> Replace Bouncy Castle with JDK Classes in StandardPrivateKeyService
> -------------------------------------------------------------------
>
>                 Key: NIFI-16409
>                 URL: https://issues.apache.org/jira/browse/NIFI-16409
>             Project: Apache NiFi
>          Issue Type: Improvement
>          Components: Extensions
>            Reporter: David Handermann
>            Assignee: David Handermann
>            Priority: Major
>          Time Spent: 1h 10m
>  Remaining Estimate: 0h
>
> The {{StandardPrivateKeyService}} currently uses the Bouncy Castle library to 
> read PEM-encoded Private Keys. Although the Bouncy Castle libraries are 
> available from the Shared NAR, these dependencies are not necessary because 
> the standard JDK provides most of the utilities needed for reading standard 
> and encrypted PKCS8 Private Key material. Some additional code will be needed 
> to implement reading Base64 encoded content and performing decryption, but 
> this follows the pattern implemented in {{nifi-security-ssl}} which supports 
> reading PEM Private Keys and Certificates for application configuration.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to