spring-projects/spring-security · error · IllegalArgumentException

Not a valid secret key

Error message

Not a valid secret key

What it means

Thrown by CipherUtils.newSecretKey when SecretKeyFactory.generateSecret(keySpec) rejects the supplied PBEKeySpec (InvalidKeySpecException). The key-derivation parameters (password chars, salt, iteration count, key length) are invalid for the requested algorithm.

Solutions

  1. Verify the PBEKeySpec keyLength matches the algorithm's output size (commonly 256 for AES-256 variants).
  2. Ensure the password char array is non-null and non-empty at the call site.
  3. On older Java 8 (<8u161) install the JCE Unlimited Strength policy files or upgrade the JDK to allow 256-bit keys.
  4. Check iteration count and salt are positive/non-empty when constructing PBEKeySpec.

Example fix

// before
PBEKeySpec spec = new PBEKeySpec(password.toCharArray(), salt, 1024, 512); // 512-bit not supported
// after
PBEKeySpec spec = new PBEKeySpec(password.toCharArray(), salt, 1024, 256);
Defensive patterns

Strategy: validation

Validate before calling

if (password == null || password.length == 0) throw new IllegalArgumentException("password required");
if (keyLengthBits != 128 && keyLengthBits != 192 && keyLengthBits != 256) throw new IllegalArgumentException("invalid keyLength");
if (salt == null || salt.length == 0) throw new IllegalArgumentException("salt required");

Try / catch

try {
    return CipherUtils.newSecretKey(algorithm, keySpec);
} catch (IllegalArgumentException ex) {
    throw new ConfigurationException("Invalid PBE key spec (check keyLength/iterations)", ex);
}

Prevention

When it happens

Trigger: Passing a PBEKeySpec whose keyLength does not match what the algorithm produces (e.g. 128 vs 256 bits), a null/empty password char array, or a spec built with parameters incompatible with the factory (e.g. zero/negative iteration count, salt length outside algorithm bounds).

Common situations: Configuring a 256-bit key on a JVM without the unlimited-strength JCE policy (older Java 8 before 8u161); building PBEKeySpec with wrong keyLength argument; salt arrays accidentally emptied by cloning/encoding bugs.

Understand the failure class

Background: "Must be a positive integer", "Invalid value", "Unsupported": the invalid-argument-value error family, when a library rejects the value you pass — this error's family across 35 libraries.

Related errors


AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10). Data as JSON: /api/errors/c336bcb0963ed0fd. Report an issue: GitHub.

Appendix: source

Thrown at crypto/src/main/java/org/springframework/security/crypto/encrypt/CipherUtils.java:66

	 * Generates a SecretKey.
	 */
	static SecretKey newSecretKey(String algorithm, String password) {
		return newSecretKey(algorithm, new PBEKeySpec(password.toCharArray()));
	}

	/**
	 * Generates a SecretKey.
	 */
	static SecretKey newSecretKey(String algorithm, PBEKeySpec keySpec) {
		try {
			SecretKeyFactory factory = SecretKeyFactory.getInstance(algorithm);
			return factory.generateSecret(keySpec);
		}
		catch (NoSuchAlgorithmException ex) {
			throw new IllegalArgumentException("Not a valid encryption algorithm", ex);
		}
		catch (InvalidKeySpecException ex) {
			throw new IllegalArgumentException("Not a valid secret key", ex);
		}
	}

	/**
	 * Constructs a new Cipher.
	 */
	static Cipher newCipher(String algorithm) {
		try {
			return Cipher.getInstance(algorithm);
		}
		catch (NoSuchAlgorithmException ex) {
			throw new IllegalArgumentException("Not a valid encryption algorithm", ex);
		}
		catch (NoSuchPaddingException ex) {
			throw new IllegalStateException("Should not happen", ex);
		}
	}

View on GitHub (pinned to 96852e8860)