SEARCH-1915 Update default keystore properties (#1003)

The defaults are now:
encryption.keyAlgorithm=AES
encryption.cipherAlgorithm=AES/CBC/PKCS5Padding
encryption.keystore.type=pkcs12
encryption.keystore.backup.type=pkcs12
This commit is contained in:
Alex Mukha
2020-05-20 10:16:40 +01:00
committed by GitHub
parent 3804c0f9cd
commit d94d57e56d
2 changed files with 9 additions and 5 deletions

View File

@@ -816,22 +816,22 @@ dir.keystore=classpath:alfresco/keystore
# general encryption parameters # general encryption parameters
encryption.keySpec.class=org.alfresco.encryption.DESEDEKeyGenerator encryption.keySpec.class=org.alfresco.encryption.DESEDEKeyGenerator
encryption.keyAlgorithm=DESede encryption.keyAlgorithm=AES
encryption.cipherAlgorithm=DESede/CBC/PKCS5Padding encryption.cipherAlgorithm=AES/CBC/PKCS5Padding
# secret key keystore configuration # secret key keystore configuration
encryption.keystore.location=${dir.keystore}/keystore encryption.keystore.location=${dir.keystore}/keystore
# configuration via metadata is deprecated # configuration via metadata is deprecated
encryption.keystore.keyMetaData.location= encryption.keystore.keyMetaData.location=
encryption.keystore.provider= encryption.keystore.provider=
encryption.keystore.type=JCEKS encryption.keystore.type=pkcs12
# backup secret key keystore configuration # backup secret key keystore configuration
encryption.keystore.backup.location=${dir.keystore}/backup-keystore encryption.keystore.backup.location=${dir.keystore}/backup-keystore
# configuration via metadata is deprecated # configuration via metadata is deprecated
encryption.keystore.backup.keyMetaData.location= encryption.keystore.backup.keyMetaData.location=
encryption.keystore.backup.provider= encryption.keystore.backup.provider=
encryption.keystore.backup.type=JCEKS encryption.keystore.backup.type=pkcs12
# Should encryptable properties be re-encrypted with new encryption keys on botstrap? # Should encryptable properties be re-encrypted with new encryption keys on botstrap?
encryption.bootstrap.reencrypt=false encryption.bootstrap.reencrypt=false

View File

@@ -61,3 +61,7 @@ system.prop_table_cleaner.algorithm=V2
# For testing only # For testing only
encryption.keystore.keyMetaData.location=${dir.keystore}/keystore-passwords.properties encryption.keystore.keyMetaData.location=${dir.keystore}/keystore-passwords.properties
encryption.keyAlgorithm=DESede
encryption.cipherAlgorithm=DESede/CBC/PKCS5Padding
encryption.keystore.type=JCEKS
encryption.keystore.backup.type=JCEKS