使用Jasypt加密密钥时遭遇EncryptionOperationNotPossibleException异常求助
Hey Vasanthakumar, sorry to hear you're stuck with this encryption issue! Let's walk through what's happening and how to fix it step by step.
First, let me recap the steps you've taken so far to make sure I'm aligned with your setup:
Your Current Configuration Steps
- Added the Jasypt Spring Boot starter dependency to your parent pom:
<dependency> <groupId>com.github.ulisesbocchio</groupId> <artifactId>jasypt-spring-boot-starter</artifactId> <version>3.0.3</version> </dependency> - Added the Jasypt Maven plugin for password encryption (planned to remove after generating encrypted values):
<plugin> <groupId>com.github.ulisesbocchio</groupId> <artifactId>jasypt-maven-plugin</artifactId> <version>3.0.3</version> </plugin> - Ran the encryption command:
mvn jasypt:encrypt-value "-Djasypt.encryptor.password=secretKey" "-Djasypt.plugin.value=secret"
The Error You're Facing
Caused by: org.jasypt.exceptions.EncryptionOperationNotPossibleException: Encryption raised an exception. A possible cause is you are using strong encryption algorithms and you have not installed the Java Cryptography Extension (JCE) Unlimited Strength Jurisdiction Policy Files in this Java Virtual Machine
What's Causing This?
Jasypt uses strong encryption algorithms (like AES-256) by default, but older Java versions (pre-Java 8 Update 161) come with restricted cryptography policies that limit key sizes. Your JVM is blocking these strong algorithms because it doesn't have the unlimited strength policy files installed.
Solutions to Fix the Issue
1. Use a Recent Java Version (Recommended)
If you're on Java 8 Update 161 or newer, or any Java 9+ version, you don't need to install separate JCE files! These versions include unlimited strength policies by default. Just double-check the crypto.policy setting in your java.security file (usually located at $JAVA_HOME/jre/lib/security or $JAVA_HOME/conf/security for newer Java):
crypto.policy=unlimited
This is already enabled by default in most recent Java builds, but it's worth verifying.
2. Install JCE Files for Older Java Versions
For Java versions before 8 Update 161:
- Download the Java Cryptography Extension (JCE) Unlimited Strength Jurisdiction Policy Files matching your Java version.
- Extract the zip file to get
local_policy.jarandUS_export_policy.jar. - Replace the existing files in your JVM's security directory (
$JAVA_HOME/jre/lib/security) with these new ones. - Restart your Maven build and re-run the encryption command.
3. Temporary Workaround: Use a Weaker Algorithm (Not for Production)
If you can't update Java or install JCE files right now, you can configure Jasypt to use a weaker algorithm that's allowed by default. This is not secure for production use, so only use it as a short-term fix.
Modify your encryption command to specify a weaker algorithm:
mvn jasypt:encrypt-value "-Djasypt.encryptor.password=secretKey" "-Djasypt.plugin.value=secret" "-Djasypt.encryptor.algorithm=PBEWithMD5AndDES"
Final Checks
After applying one of the fixes above, re-run your encryption command. It should execute without throwing the EncryptionOperationNotPossibleException error. If you still have issues, make sure your JAVA_HOME environment variable points to the correct JVM where you installed the policies (if applicable).
备注:内容来源于stack exchange,提问作者Vasanthakumar Jagannathan

