Re: Problems with encrypted CMS with Luna HSM and JBOSS
Massimiliano Ziccardi <[email protected]> Mon, 27 May 2019 14:52:45 +0200
| Newsgroups | gmane.comp.encryption.bouncy-castle.devel |
|---|---|
| Message-ID | <CAPwY8YD=sJH-2S0wN7En77LG8S1Eg2ZjYzhVd89e0w+nYtX=sw@mail.gmail.com> |
The question could sound stupid, but have you ensured that both servers are accessing the same HSM and the same slots? Il giorno lun 27 mag 2019 alle ore 12:59 Emiliano Latini < [email protected]> ha scritto: > Hi there. > > I’m trying to decrypt an encrypted p7m using BC along with HSM. > > The code works well on a standalone machine i.e tomcat, if I run it in a > Jboss Domain mode I get only one node to work. > > The other gets this exception: function 'C_UnwrapKey' returns 0x110 on > key=xxxxxxx note this key doesn’t exist on the HSM so I suppose it’s trying > to put the extracted key > > > > This is part of the stack : > > > > Caused by: com.safenetinc.luna.exception.LunaException: Unable to inject > key > > at > com.safenetinc.luna.provider.key.LunaKey.injectKey(LunaKey.java:801) > > at > com.safenetinc.luna.provider.key.LunaSecretKey.InjectSecretKey(LunaSecretKey.java:139) > > at > com.safenetinc.luna.provider.key.LunaSecretKey.InjectSecretKey(LunaSecretKey.java:121) > > at > com.safenetinc.luna.provider.keyfactory.LunaSecretKeyFactoryDES3.engineTranslateKey(LunaSecretKeyFactoryDES3.java:91) > > at > javax.crypto.SecretKeyFactory.translateKey(SecretKeyFactory.java:409) > > at > com.safenetinc.luna.provider.cipher.LunaCipher.engineInit(LunaCipher.java:336) > > at > com.safenetinc.luna.provider.cipher.LunaCipherIv.engineInit(LunaCipherIv.java:64) > > at javax.crypto.Cipher.init(Cipher.java:1393) > > at javax.crypto.Cipher.init(Cipher.java:1326) > > at > org.bouncycastle.cms.jcajce.EnvelopedDataHelper$1.doInJCE(Unknown Source) > > at > org.bouncycastle.cms.jcajce.EnvelopedDataHelper.execute(Unknown Source) > > at > org.bouncycastle.cms.jcajce.EnvelopedDataHelper.createContentCipher(Unknown > Source) > > at > org.bouncycastle.cms.jcajce.JceKeyTransEnvelopedRecipient.getRecipientOperator(Unknown > Source) > > at > org.bouncycastle.cms.KeyTransRecipientInformation.getRecipientOperator(Unknown > Source) > > at > org.bouncycastle.cms.RecipientInformation.getContentStream(Unknown Source) > > > > > > And this is the code I use for it: > > > > RecipientInformation recipient = recipients.get(new > JceKeyTransRecipientId((java.security.cert.X509Certificate)jcaProvider.getKeystore().getCertificate(alias))); > > if (recipient != null) { > > log.info("recipient!=null getting > trans"); > > > > JceKeyTransEnvelopedRecipient trans=new > JceKeyTransEnvelopedRecipient((PrivateKey)jcaProvider.getKeystore().getKey(alias,jcaProvider.getPwd().toCharArray())); > > > > > trans.setMustProduceEncodableUnwrappedKey(true); > > trans.setProvider(provider); > > > > log.info("returning content!"); > > > > CMSTypedStream cmsTs= > recipient.getContentStream(trans); > > return cmsTs.getContentStream(); > > > > > > } > > > > Still don’t understand why it works only on a node since it seems a > problem with keys…any ideas? > > Thank you > > > > > > *Emiliano Latini* > > *Engineering's Software Laboratory* > > Direct: +39 06 87594577 > Mobile: +39 347 7906590 > > E-mail : [email protected] > > > *Engineering Ingegneria Informatica spa Piazzale dell’Agricoltura, 24 - > 00144 Roma* > > *Segui Engineering su Twitter! (@EngineeringSpA)* > > *www.eng.it <http://www.eng.it/> * > > > > >