spring-projects/spring-security · error · IllegalArgumentException
Not a valid secret key
Error message
Not a valid secret key
What it means
Thrown by CipherUtils.newSecretKey when SecretKeyFactory.generateSecret(keySpec) rejects the supplied PBEKeySpec (InvalidKeySpecException). The key-derivation parameters (password chars, salt, iteration count, key length) are invalid for the requested algorithm.
Solutions
- Verify the PBEKeySpec keyLength matches the algorithm's output size (commonly 256 for AES-256 variants).
- Ensure the password char array is non-null and non-empty at the call site.
- On older Java 8 (<8u161) install the JCE Unlimited Strength policy files or upgrade the JDK to allow 256-bit keys.
- Check iteration count and salt are positive/non-empty when constructing PBEKeySpec.
Example fix
// before PBEKeySpec spec = new PBEKeySpec(password.toCharArray(), salt, 1024, 512); // 512-bit not supported // after PBEKeySpec spec = new PBEKeySpec(password.toCharArray(), salt, 1024, 256);
Defensive patterns
Strategy: validation
Validate before calling
if (password == null || password.length == 0) throw new IllegalArgumentException("password required");
if (keyLengthBits != 128 && keyLengthBits != 192 && keyLengthBits != 256) throw new IllegalArgumentException("invalid keyLength");
if (salt == null || salt.length == 0) throw new IllegalArgumentException("salt required"); Try / catch
try {
return CipherUtils.newSecretKey(algorithm, keySpec);
} catch (IllegalArgumentException ex) {
throw new ConfigurationException("Invalid PBE key spec (check keyLength/iterations)", ex);
} Prevention
- Use 256-bit keyLength with adequate iteration counts (e.g. >=1024 per Spring defaults).
- Ensure JDK >= 8u161 or install unlimited-strength policy for AES-256.
- Validate password/salt inputs at config load time, not lazily on first encryption.
- Reuse the library's factory methods rather than hand-building PBEKeySpec.
When it happens
Trigger: Passing a PBEKeySpec whose keyLength does not match what the algorithm produces (e.g. 128 vs 256 bits), a null/empty password char array, or a spec built with parameters incompatible with the factory (e.g. zero/negative iteration count, salt length outside algorithm bounds).
Common situations: Configuring a 256-bit key on a JVM without the unlimited-strength JCE policy (older Java 8 before 8u161); building PBEKeySpec with wrong keyLength argument; salt arrays accidentally emptied by cloning/encoding bugs.
Understand the failure class
Background: "Must be a positive integer", "Invalid value", "Unsupported": the invalid-argument-value error family, when a library rejects the value you pass — this error's family across 35 libraries.
Related errors
- Bad salt length
- Could not create hash
- Invalid log_rounds
- Invalid prefix
- Iterations value must be greater than zero
AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10).
Data as JSON: /api/errors/c336bcb0963ed0fd.
Report an issue: GitHub.
Appendix: source
Thrown at crypto/src/main/java/org/springframework/security/crypto/encrypt/CipherUtils.java:66
* Generates a SecretKey.
*/
static SecretKey newSecretKey(String algorithm, String password) {
return newSecretKey(algorithm, new PBEKeySpec(password.toCharArray()));
}
/**
* Generates a SecretKey.
*/
static SecretKey newSecretKey(String algorithm, PBEKeySpec keySpec) {
try {
SecretKeyFactory factory = SecretKeyFactory.getInstance(algorithm);
return factory.generateSecret(keySpec);
}
catch (NoSuchAlgorithmException ex) {
throw new IllegalArgumentException("Not a valid encryption algorithm", ex);
}
catch (InvalidKeySpecException ex) {
throw new IllegalArgumentException("Not a valid secret key", ex);
}
}
/**
* Constructs a new Cipher.
*/
static Cipher newCipher(String algorithm) {
try {
return Cipher.getInstance(algorithm);
}
catch (NoSuchAlgorithmException ex) {
throw new IllegalArgumentException("Not a valid encryption algorithm", ex);
}
catch (NoSuchPaddingException ex) {
throw new IllegalStateException("Should not happen", ex);
}
}
View on GitHub (pinned to 96852e8860)