You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security 5.2.0中Argon2PasswordEncoder缺失BouncyCastle依赖问询

Understanding Argon2PasswordEncoder's BouncyCastle Dependency in Spring Security 5.2.0

Great question—this is a common point of confusion with optional security features in Spring Security, so let's unpack it clearly:

Why isn't BouncyCastle listed as an optional dependency?

Spring Security's core design focuses on keeping its core dependency footprint as lean as possible. The Argon2PasswordEncoder is an optional, non-default password encoder (most users stick with BCrypt, which doesn't rely on external crypto libraries).

Instead of adding BouncyCastle as an optional dependency (which would still add unnecessary clutter to dependency graphs for users who never use Argon2), the team chose to document the requirement explicitly and leave dependency management to developers who need this specific encoder. This way, users who don't use Argon2 don't have to pull in extra crypto libraries they'll never use.

How to pick the right BouncyCastle version?

You don't have to guess—there are reliable ways to find a compatible version:

  • Leverage Spring's dependency management: If you're using Spring Boot, the parent POM already defines a compatible BouncyCastle version that works with Spring Security 5.2.0. Just add the dependency without specifying a version, and Spring Boot will handle the rest.
  • Match Spring Security's tested versions: Check the versions used in Spring Security 5.2.0's test suite. For example, Spring Security 5.2.x typically uses BouncyCastle versions like 1.62 or 1.65—these are guaranteed to work since they're used in official tests.
  • Use the correct artifact variant: Stick with bcprov-jdk15on (not older variants like bcprov-jdk14), as it's compatible with modern JDK versions and aligns with what Spring Security expects for Argon2 support.

Here's an example of how to add it to your pom.xml:

<dependency>
    <groupId>org.bouncycastle</groupId>
    <artifactId>bcprov-jdk15on</artifactId>
    <version>1.62</version> <!-- Or the version recommended by Spring Security's docs/test suite -->
</dependency>

Quick validation tip

After adding the dependency, run a simple test to encode and verify a password with Argon2PasswordEncoder:

Argon2PasswordEncoder encoder = new Argon2PasswordEncoder();
String encoded = encoder.encode("testPassword");
assert encoder.matches("testPassword", encoded);

If this runs without ClassNotFoundException or NoSuchMethodError, your version is compatible.

内容的提问来源于stack exchange,提问作者Rasha Elsayed

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:23:34