Skip to content

Support AES-256 for internal encryption #4692

@AqeelMuhammad

Description

@AqeelMuhammad

Description

Currently in APIM, it works with the RSA asymmetric encryption with RSA/ECB/OAEPwithSHA1andMGF1Padding. We need to change it for AES/GCM/NoPadding to support symmetric key encryption by default.

Below are some identified points where it uses encryption internally.

  1. Backend security secrets - Publisher Portal
  2. Key Manager secrets - Admin Portal
  3. Gateway secrets - Admin Portal
  4. API Policy secrets - Publisher Portal
  5. Access Tokens - Developer Portal
  6. Mediation Policy secrets - Publisher Portal
  7. User store config credentials - Carbon Console

Version

4.7.0

Metadata

Metadata

Assignees

Labels

Projects

Status

In Progress

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions