【问题标题】:Spring Cloud Config Server encryption issueSpring Cloud Config Server 加密问题
【发布时间】:2020-09-05 01:49:24
【问题描述】:

我们有一个 Pivotal Cloud Foundry 服务器,它配置了一个带有加密密钥的 Spring 配置服务器。在相应的属性文件(通过 github)中,我们为一些简单的属性添加了 {cipher} 前缀,并且我们能够在应用程序中很好地获取这些值。但我们最近注意到的挑战是,当我们有一个 base64 数据需要加密时,spring 加密会截断 base64 数据末尾的尾随等号。当我们的应用程序读取此数据时,由于它不是有效的 base64,因为它在末尾的填充字符(等号)丢失,因此解析失败。我们尝试用反斜杠转义等号,但仍然没有运气。我们只是看到两个反斜杠,所以想知道是否有任何建议可以解决这个问题。谢谢!

【问题讨论】:

  • 您如何尝试加密该值?能给我举个例子吗?仅供参考,如果您从命令行运行命令,您可能是 shell 转义的受害者。如果您使用的是 Linux/Unix shell,请尝试在值周围使用单引号。
  • 谢谢,这是详细信息。 VGVzdC0= 是 Test- 的 base64 等价物,这是我需要的字符串。我们使用命令curl -k -H "Authorization: $oauth" $config_url/encrypt -d "VGVzdC0=" 当应用程序从SprintConfigServer 获取值时,它获取的值是VGVzdC0。所以我的 base64 解析器会失败,因为它最后没有看到强制填充字符“=”。
  • 我们在 windows 机器上使用 git bash shell。我们一直在使用这个 shell 成功地加密其他应用程序,并为生产环境生成我们所有的密钥,我们从未发现任何问题。再次感谢。
  • 你能分享一些关于你在这里使用的版本的细节吗?您使用的是 OSS Spring Cloud Config Server 还是 Pivotal 的 Spring Cloud Config Server?在您的客户端应用程序中,哪些版本的 Spring Boot、Spring Cloud,以及如果使用 Pivotal SCS,Pivotal SCS 依赖项?谢谢
  • 我们使用的是 Pivotal Sprint 云配置服务器,v-2.7(更低)和 v-2.4(产品)。我们有 TIBCO BusinessWorks Container Edition 以及 SprintBoot 服务。从直接属性的角度来看,我们没有看到任何问题,因为 base64 属性值被解释得很好(最后带有 = 符号),但唯一的故障是当这个值通过 Spring Cloud 被提供给我们的服务时配置服务器。所以我们看到 PCF Spring Cloud Config Server 是罪魁祸首。我也想知道是否有任何选择来逃避角色或其他东西。谢谢@DanielMikusa!

标签: cloud-foundry spring-cloud-config spring-cloud-config-server


【解决方案1】:

据我所知,这里的问题似乎与curl 的使用有关。我可以通过运行复制您看到的问题:

spring decrypt --key @${HOME}/server_rsa_no_eol.key "$(curl -H "Authorization: $(cf oauth-token)" https://config-server.example.com/encrypt -s -d 'VGVzdC0=')"

这使用curl 访问加密端点并获取结果并立即使用spring decrypt 对其进行解密。正如您所指出的,这将返回 VGVzdC0。

这似乎是一个 curl 问题,因为我可以在 https://httpbin.org/post 上发布相同的帖子,并且得到相同的结果,VGVzdC0 没有 =。

$ curl https://httpbin.org/post --data 'VGVzdC0='
{
  ...
  "form": {
    "VGVzdC0": ""
  },
  ...

如果我对 = 字符进行 url 编码,那么可行。

$ curl https://httpbin.org/post --data 'VGVzdC0%3D'
{
  ...
  "form": {
    "VGVzdC0=": ""
  },
  ...

您也可以使用--data-urlencode 使curl 进行url 编码,但有一个问题。您必须在该值前面加上 =。所以这也有效

$ curl https://httpbin.org/post --data-urlencode '=VGVzdC0='
{
  "args": {},
  "data": "",
  "files": {},
  "form": {
    "VGVzdC0=": ""
  },
...

来自 curl 手册页:

  --data-urlencode <data>
          (HTTP) This posts data, similar to the other -d, --data options with the exception that this performs URL-encoding.

          To be CGI-compliant, the <data> part should begin with a name followed by a separator and a content specification. The <data> part can be passed to curl using one of the following
          syntaxes:

          content
                 This will make curl URL-encode the content and pass that on. Just be careful so that the content doesn't contain any = or @ symbols, as that will then make the syntax match
                 one of the other cases below!

          =content
                 This will make curl URL-encode the content and pass that on. The preceding = symbol is not included in the data.

关键是最后一部分=content。这将使 curl url 对内容进行编码,并且不包括前缀 =。

如果我重复上面的测试,我会得到预期的结果VGVzdC0=。

spring decrypt --key @${HOME}/server_rsa_no_eol.key "$(curl -H "Authorization: $(cf oauth-token)" https://config-server.example.com/encrypt -s --data-urlencode '=VGVzdC0=')"

顺便说一句,您还可以选择简单的选项并安装 Spring Boot CLI + Spring Cloud Extension。然后你可以spring encrypt --key @${HOME}/server_rsa_no_eol.key 'VGVzdC0=' 并且你会得到正确的值。这确实意味着您需要本地计算机上的密钥副本,您可能拥有也可能没有。

brew install springboot
spring install org.springframework.cloud:spring-cloud-cli:2.2.1.RELEASE

【讨论】:

  • @Astronet-K2 这有帮助吗?如果没有,请告诉我。
  • 这很有帮助。非常感谢你们@Daniel 和 halfer 的帮助。
【解决方案2】:

使用httpie可以避免curl引起的问题:

加密:

echo -n cleartext | http https://config-server.com/encrypt

解密:

echo -n ciphertext | http https://config-server.com/decrypt

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 2022-01-14
    • 2016-09-26
    • 2020-11-06
    • 2016-09-29
    • 1970-01-01
    • 1970-01-01
    • 2017-01-27
    • 1970-01-01
    相关资源
    最近更新 更多