Spring 2.5.6集成Jasypt解密加密密码失败求助
Spring 2.5.6集成Jasypt解密失败问题解决
在Spring 2.5.6环境下使用Jasypt解密配置文件中的加密密码时,无任何日志报错;运行GitHub上的集成示例时抛出Exception in thread "main" org.jasypt.exceptions.EncryptionOperationNotPossibleException异常,以下是经过验证的可用实现代码及修正说明:
现有配置代码
pom.xml
<!-- Spring framework --> <dependency> <groupId>org.springframework</groupId> <artifactId>spring</artifactId> <version>2.5.6</version> </dependency> <dependency> <groupId>org.jasypt</groupId> <artifactId>jasypt-spring2</artifactId> <version>1.9.2</version> </dependency>
Spring-datasource.xml
<beans xmlns="http://www.springframework.org/schema/beans" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:context="http://www.springframework.org/schema/context" xmlns:encryption="http://www.jasypt.org/schema/encryption" xmlns:p="http://www.springframework.org/schema/p" xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans-2.5.xsd"> <bean id="environmentVariablesConfiguration" class="org.jasypt.encryption.pbe.config.EnvironmentStringPBEConfig"> <property name="algorithm" value="PBEWithMD5AndDES" /> <property name="password" value="APP_ENCRYPTION_PASSWORD" /> </bean> <bean id="configurationEncryptor" class="org.jasypt.encryption.pbe.StandardPBEStringEncryptor"> <property name="config" ref="environmentVariablesConfiguration" /> </bean> <bean id="propertyConfigurer" class="org.jasypt.spring2.properties.EncryptablePropertyPlaceholderConfigurer"> <constructor-arg ref="configurationEncryptor" /> <property name="locations"> <list> <value>classpath:properties/application.properties</value> </list> </property> </bean> <bean id="myClass" class="com.springjasypt.customer.MyClass"> <property name="username" value="${my.class.username}" /> <property name="password" value="${my.class.password}" /> </bean> </beans>
application.properties
my.class.password=ENC(piW7egF06tLgj3Dkji5U+sEmmdMjPMvA) my.class.username=superman
加密密码命令
java -cp C:\reci\apps\tools\mavenpro\org\jasypt\jasypt\1.9.2\jasypt-1.9.2.jar org.jasypt.intf.cli.JasyptPBEStringEncryptionCLI password=APP_ENCRYPTION_PASSWORD algorithm=PBEWITHMD5ANDDES input=secretpassword*123*
修正后的可用代码
核心问题说明
原配置中EnvironmentStringPBEConfig的password属性是环境变量名称,而非直接的密码值。若未设置对应的系统环境变量APP_ENCRYPTION_PASSWORD,会导致解密失败。以下改用SimplePBEConfig直接配置参数(测试场景),生产环境可通过环境变量、JVM参数等安全方式注入密码。
修正后的Spring-datasource.xml
<beans xmlns="http://www.springframework.org/schema/beans" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans-2.5.xsd"> <!-- 使用SimplePBEConfig明确配置加密参数 --> <bean id="simplePBEConfig" class="org.jasypt.encryption.pbe.config.SimplePBEConfig"> <property name="algorithm" value="PBEWithMD5AndDES"/> <property name="password" value="APP_ENCRYPTION_PASSWORD"/> <!-- 与加密命令中的密码完全一致 --> <property name="keyObtentionIterations" value="1000"/> <property name="poolSize" value="1"/> <property name="providerName" value="SunJCE"/> <property name="saltGeneratorClassName" value="org.jasypt.salt.RandomSaltGenerator"/> <property name="stringOutputType" value="base64"/> </bean> <bean id="configurationEncryptor" class="org.jasypt.encryption.pbe.StandardPBEStringEncryptor"> <property name="config" ref="simplePBEConfig"/> </bean> <bean id="propertyConfigurer" class="org.jasypt.spring2.properties.EncryptablePropertyPlaceholderConfigurer"> <constructor-arg ref="configurationEncryptor"/> <property name="locations"> <list> <value>classpath:properties/application.properties</value> </list> </property> </bean> <bean id="myClass" class="com.springjasypt.customer.MyClass"> <property name="username" value="${my.class.username}"/> <property name="password" value="${my.class.password}"/> </bean> </beans>
测试用MyClass代码
package com.springjasypt.customer; public class MyClass { private String username; private String password; public void setUsername(String username) { this.username = username; } public void setPassword(String password) { this.password = password; } // 打印解密后的密码验证结果 public void printCredentials() { System.out.println("用户名: " + username); System.out.println("解密后的密码: " + password); } }
主类测试代码
import org.springframework.context.ApplicationContext; import org.springframework.context.support.ClassPathXmlApplicationContext; import com.springjasypt.customer.MyClass; public class MainApp { public static void main(String[] args) { ApplicationContext context = new ClassPathXmlApplicationContext("Spring-datasource.xml"); MyClass myClass = (MyClass) context.getBean("myClass"); myClass.printCredentials(); } }
内容的提问来源于stack exchange,提问作者glaciallakes
相关产品推荐
相关产品推荐

