从AWS Secrets Manager获取PGP私钥时提示“No key data found”问题
PGPainless生产环境解密故障排查方案
核心问题定位
本地通过Docker加载秘钥JSON可正常解密,但将秘钥复制到AWS Secrets Manager后,Java读取私钥提示No key data found,大概率是秘钥在存储/传输过程中格式或编码被篡改。
解决步骤
强制指定UTF-8编码转换
系统默认编码可能导致字节流不一致,明确使用UTF-8转换字符串到字节数组:import java.nio.charset.StandardCharsets; byte[] keyBytes = ourSecretsService.getPgpPrivateKey().getBytes(StandardCharsets.UTF_8);修复转义的换行符
AWS Secrets Manager可能会将秘钥中的换行符转义为\\n,需要还原后再处理:String rawKey = ourSecretsService.getPgpPrivateKey().replace("\\n", "\n"); byte[] keyBytes = rawKey.getBytes(StandardCharsets.UTF_8);可以先打印
rawKey的内容,对比本地秘钥的换行格式,确认是否存在转义问题。显式加载PGP秘钥环
改用PGPainless的KeyRingReader加载秘钥,兼容格式修复:import org.pgpainless.PGPainless; import org.pgpainless.keyring.PGPSecretKeyRing; String rawKey = ourSecretsService.getPgpPrivateKey(); // 补全标准PGP私钥的头尾标记(如果缺失) if (!rawKey.startsWith("-----BEGIN PGP PRIVATE KEY BLOCK-----")) { rawKey = "-----BEGIN PGP PRIVATE KEY BLOCK-----\n" + rawKey + "\n-----END PGP PRIVATE KEY BLOCK-----"; } PGPSecretKeyRing secretKeyRing = PGPainless.readKeyRing().secretKeyRing(rawKey.getBytes(StandardCharsets.UTF_8)); byte[] resultBytes = sop.decrypt() .withKey(secretKeyRing) .withKeyPassword(keyPassword) .ciphertext(encryptedFileBytes) .toByteArrayAndResult() .getBytes();验证AWS秘钥存储格式
用AWS CLI导出秘钥到本地,和原始秘钥对比:aws secretsmanager get-secret-value --secret-id 你的秘钥ID --query SecretString --output text > aws-pgp-key.txt diff 本地原始秘钥文件.txt aws-pgp-key.txt检查是否存在字符截断、额外空格或格式差异。
内容的提问来源于stack exchange,提问作者tlhinman
相关产品推荐
相关产品推荐

