Jasypt StandardPBEStringEncryptor installation password in spring bean configuration file

When using Jasypt StandardPBEStringEncryptor, we must explicitly set the password in the spring bean configuration file. Is it safe and safe to have a password in the bean configuration file? Will the PCI Compliance problem keep the encryption password?

+3
source share
2 answers

This one will not be compatible with PCI. Data encryption keys cannot be stored in clear text. The specific point is 3.5.2, which:

, , .

, , 3.6.6 ( )

, , (, , , ).

PCI-. , ( PCI) . , QSA (PCI Qualified Security Assesor) , . , QSA, , PCI, .

+1

-. , .

0

Source: https://habr.com/ru/post/1755985/


All Articles