{"record":{"id":"c336bcb0963ed0fd","repo":"spring-projects/spring-security","slug":"not-a-valid-secret-key","errorCode":null,"errorMessage":"Not a valid secret key","messagePattern":"Not a valid secret key","errorType":"exception","errorClass":"IllegalArgumentException","httpStatus":null,"severity":"error","filePath":"crypto/src/main/java/org/springframework/security/crypto/encrypt/CipherUtils.java","lineNumber":66,"sourceCode":"\t * Generates a SecretKey.\n\t */\n\tstatic SecretKey newSecretKey(String algorithm, String password) {\n\t\treturn newSecretKey(algorithm, new PBEKeySpec(password.toCharArray()));\n\t}\n\n\t/**\n\t * Generates a SecretKey.\n\t */\n\tstatic SecretKey newSecretKey(String algorithm, PBEKeySpec keySpec) {\n\t\ttry {\n\t\t\tSecretKeyFactory factory = SecretKeyFactory.getInstance(algorithm);\n\t\t\treturn factory.generateSecret(keySpec);\n\t\t}\n\t\tcatch (NoSuchAlgorithmException ex) {\n\t\t\tthrow new IllegalArgumentException(\"Not a valid encryption algorithm\", ex);\n\t\t}\n\t\tcatch (InvalidKeySpecException ex) {\n\t\t\tthrow new IllegalArgumentException(\"Not a valid secret key\", ex);\n\t\t}\n\t}\n\n\t/**\n\t * Constructs a new Cipher.\n\t */\n\tstatic Cipher newCipher(String algorithm) {\n\t\ttry {\n\t\t\treturn Cipher.getInstance(algorithm);\n\t\t}\n\t\tcatch (NoSuchAlgorithmException ex) {\n\t\t\tthrow new IllegalArgumentException(\"Not a valid encryption algorithm\", ex);\n\t\t}\n\t\tcatch (NoSuchPaddingException ex) {\n\t\t\tthrow new IllegalStateException(\"Should not happen\", ex);\n\t\t}\n\t}\n","sourceCodeStart":48,"sourceCodeEnd":84,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/crypto/src/main/java/org/springframework/security/crypto/encrypt/CipherUtils.java#L48-L84","documentation":"Thrown by CipherUtils.newSecretKey when SecretKeyFactory.generateSecret(keySpec) rejects the supplied PBEKeySpec (InvalidKeySpecException). The key-derivation parameters (password chars, salt, iteration count, key length) are invalid for the requested algorithm.","triggerScenarios":"Passing a PBEKeySpec whose keyLength does not match what the algorithm produces (e.g. 128 vs 256 bits), a null/empty password char array, or a spec built with parameters incompatible with the factory (e.g. zero/negative iteration count, salt length outside algorithm bounds).","commonSituations":"Configuring a 256-bit key on a JVM without the unlimited-strength JCE policy (older Java 8 before 8u161); building PBEKeySpec with wrong keyLength argument; salt arrays accidentally emptied by cloning/encoding bugs.","solutions":["Verify the PBEKeySpec keyLength matches the algorithm's output size (commonly 256 for AES-256 variants).","Ensure the password char array is non-null and non-empty at the call site.","On older Java 8 (<8u161) install the JCE Unlimited Strength policy files or upgrade the JDK to allow 256-bit keys.","Check iteration count and salt are positive/non-empty when constructing PBEKeySpec."],"exampleFix":"// before\nPBEKeySpec spec = new PBEKeySpec(password.toCharArray(), salt, 1024, 512); // 512-bit not supported\n// after\nPBEKeySpec spec = new PBEKeySpec(password.toCharArray(), salt, 1024, 256);","handlingStrategy":"validation","validationCode":"if (password == null || password.length == 0) throw new IllegalArgumentException(\"password required\");\nif (keyLengthBits != 128 && keyLengthBits != 192 && keyLengthBits != 256) throw new IllegalArgumentException(\"invalid keyLength\");\nif (salt == null || salt.length == 0) throw new IllegalArgumentException(\"salt required\");","typeGuard":null,"tryCatchPattern":"try {\n    return CipherUtils.newSecretKey(algorithm, keySpec);\n} catch (IllegalArgumentException ex) {\n    throw new ConfigurationException(\"Invalid PBE key spec (check keyLength/iterations)\", ex);\n}","preventionTips":["Use 256-bit keyLength with adequate iteration counts (e.g. >=1024 per Spring defaults).","Ensure JDK >= 8u161 or install unlimited-strength policy for AES-256.","Validate password/salt inputs at config load time, not lazily on first encryption.","Reuse the library's factory methods rather than hand-building PBEKeySpec."],"tags":["crypto","secret-key","pbe","keyspec","spring-security"],"backgroundTag":"invalid-argument-value","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}