You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot Config Server遇Jasypt DecryptionException异常如何解决

Spring Boot Config Server Jasypt 解密失败问题排查与解决

问题描述

在Spring Boot微服务的Config Server中集成jasypt-spring-boot-starter实现配置加密:

  1. 引入依赖:
<dependency>
    <groupId>com.github.ulisesbocchio</groupId>
    <artifactId>jasypt-spring-boot-starter</artifactId>
</dependency>
  1. 编写测试代码验证加密解密功能,测试通过:
public static void main(String[] args) {
    StandardPBEStringEncryptor standardPBEStringEncryptor = new StandardPBEStringEncryptor();
    standardPBEStringEncryptor.setPassword("demo-password");
    standardPBEStringEncryptor.setAlgorithm("PBEWithHMACSHA512AndAES_256");
    standardPBEStringEncryptor.setIvGenerator(new RandomIvGenerator());
    String result = standardPBEStringEncryptor.encrypt("spring-cloud-password");
    System.out.println(result);
    System.out.println(standardPBEStringEncryptor.decrypt(result));
}
  1. 将加密后的密码用ENC()包裹写入yml配置文件:
spring:
  application:
    name: configserver
  cloud:
    config:
      server:
        git:
          uri: Github-repo-address
          username: Github-username
          password: github-token
          clone-on-start: true
          default-label: main
    fail-fast: true

  security:
    user:
      name: spring-cloud-user
      password: ENC(YcplhYriW9Uwo+pByJxBl04lqiQKGEIbBgVeIXn+DBITIHV9IUVenfknA2VHFswkm144fSrQRqjxZ17+g+z3GA==)

jasypt:
  encryptor:
    password: ${PASSWORD}
  1. 通过程序参数传递密钥启动:-Djasypt.encryptor.password='Demo_Pwd!2020',但启动时抛出异常:
com.ulisesbocchio.jasyptspringboot.exception.DecryptionException: Unable to decrypt: ENC(YcplhYriW9Uwo+pByJxBl04lqiQKGEIbBgVeIXn+DBITIHV9IUVenfknA2VHFswkm144fSrQRqjxZ17+g+z3GA==). Decryption of Properties failed,  make sure encryption/decryption passwords match
    at com.ulisesbocchio.jasyptspringboot.resolver.DefaultPropertyResolver.lambda$resolvePropertyValue$0(DefaultPropertyResolver.java:46)
    ...
Caused by: org.jasypt.exceptions.EncryptionOperationNotPossibleException: null
    ...

解决方案

1. 对齐加密解密密钥

测试代码中使用的密钥是demo-password,但启动时传递的是Demo_Pwd!2020,二者完全不一致,这是核心问题。必须保证加密时使用的密钥和启动时传递的密钥完全相同。

2. 统一加密器配置参数

手动测试代码中指定了加密算法和IV生成器,但Spring Boot集成Jasypt时默认配置可能不同,需要在yml中显式配置一致的参数:

jasypt:
  encryptor:
    password: ${PASSWORD}
    algorithm: PBEWithHMACSHA512AndAES_256
    iv-generator-classname: org.jasypt.iv.RandomIvGenerator

3. 修正启动参数格式

启动参数中的引号可能导致密钥解析错误,不同系统处理逻辑不同:

  • Linux/macOS:直接传递无引号的参数,若含特殊字符可加单引号:-Djasypt.encryptor.password=Demo_Pwd!2020
  • Windows:若密钥含特殊字符,用双引号包裹:-Djasypt.encryptor.password="Demo_Pwd!2020"

4. 重新生成加密密码

使用正确的密钥(与启动时要传递的一致)修改测试代码,重新生成加密串,替换配置文件中的旧值:

standardPBEStringEncryptor.setPassword("Demo_Pwd!2020"); // 替换为启动时要用的密钥

内容的提问来源于stack exchange,提问作者Sercan Noyan Germiyanoğlu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.07 03:01:12