Skip to content

Commit 6dff74e

Browse files
committed
Clean up obsolete ESAPI 1.4 comments in config files
ESAPI 1.4 is past EOL and the old encrypt(String)/decrypt(String) compatibility APIs are gone. Drop the leftover 1.4 migration notes from ESAPI.properties copies and the matching javadoc. Fixes #474
1 parent 1556282 commit 6dff74e

6 files changed

Lines changed: 5 additions & 124 deletions

‎src/main/java/org/owasp/esapi/SecurityConfiguration.java‎

Lines changed: 5 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -239,10 +239,9 @@ public interface SecurityConfiguration extends EsapiPropertyLoader {
239239
String getUsernameParameterName();
240240

241241
/**
242-
* Gets the encryption algorithm used by ESAPI to protect data. This is
243-
* mostly used for compatibility with ESAPI 1.4; ESAPI 2.0 prefers to
244-
* use "cipher transformation" since it supports multiple cipher modes
245-
* and padding schemes.
242+
* Gets the encryption algorithm used by ESAPI to protect data.
243+
* ESAPI 2.x prefers to use "cipher transformation" since it supports
244+
* multiple cipher modes and padding schemes.
246245
*
247246
* @return the current encryption algorithm
248247
* @deprecated Use SecurityConfiguration.getStringProp("appropriate_esapi_prop_name") instead.
@@ -271,8 +270,8 @@ public interface SecurityConfiguration extends EsapiPropertyLoader {
271270
* </p><p>
272271
* Examples are:
273272
* <pre>
274-
* "AES/ECB/NoPadding" // Default for ESAPI Java 1.4 (insecure)
275-
* "AES/CBC/PKCS5Padding" // Default for ESAPI Java 2.0
273+
* "AES/ECB/NoPadding" // Insecure; do not use
274+
* "AES/CBC/PKCS5Padding" // Default for ESAPI 2.x
276275
* "DESede/OFB32/PKCS5Padding"
277276
* </pre>
278277
* <b>NOTE:</b> Occasionally, in cryptographic literature, you may also

‎src/test/resources/esapi/ESAPI-CommaValidatorFileChecker.properties‎

Lines changed: 0 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -63,12 +63,6 @@
6363
# get updated dynamically.
6464
#
6565
# Before using, be sure to update the MasterKey and MasterSalt as described below.
66-
# N.B.: If you had stored data that you have previously encrypted with ESAPI 1.4,
67-
# you *must* FIRST decrypt it using ESAPI 1.4 and then (if so desired)
68-
# re-encrypt it with ESAPI 2.0. If you fail to do this, you will NOT be
69-
# able to decrypt your data with ESAPI 2.0.
70-
#
71-
# YOU HAVE BEEN WARNED!!! More details are in the ESAPI 2.0 Release Notes.
7266
#
7367
#===========================================================================
7468
# ESAPI Configuration
@@ -158,21 +152,6 @@ Encoder.DefaultCodecList=HTMLEntityCodec,PercentCodec,JavaScriptCodec
158152
# unlimited strength policy files and install in the lib directory of your JRE/JDK.
159153
# See http://java.sun.com/javase/downloads/index.jsp for more information.
160154
#
161-
# Backward compatibility with ESAPI Java 1.4 is supported by the two deprecated API
162-
# methods, Encryptor.encrypt(String) and Encryptor.decrypt(String). However, whenever
163-
# possible, these methods should be avoided as they use ECB cipher mode, which in almost
164-
# all circumstances a poor choice because of it's weakness. CBC cipher mode is the default
165-
# for the new Encryptor encrypt / decrypt methods for ESAPI Java 2.0. In general, you
166-
# should only use this compatibility setting if you have persistent data encrypted with
167-
# version 1.4 and even then, you should ONLY set this compatibility mode UNTIL
168-
# you have decrypted all of your old encrypted data and then re-encrypted it with
169-
# ESAPI 2.0 using CBC mode. If you have some reason to mix the deprecated 1.4 mode
170-
# with the new 2.0 methods, make sure that you use the same cipher algorithm for both
171-
# (256-bit AES was the default for 1.4; 128-bit is the default for 2.0; see below for
172-
# more details.) Otherwise, you will have to use the new 2.0 encrypt / decrypt methods
173-
# where you can specify a SecretKey. (Note that if you are using the 256-bit AES,
174-
# that requires downloading the special jurisdiction policy files mentioned above.)
175-
#
176155
# ***** IMPORTANT: These are for JUnit testing. Test files may have been
177156
# encrypted using these values so do not change these or
178157
# those tests will fail. The version under
@@ -219,12 +198,6 @@ Encryptor.PreferredJCEProvider=
219198

220199
# AES is the most widely used and strongest encryption algorithm. This
221200
# should agree with your Encryptor.CipherTransformation property.
222-
# By default, ESAPI Java 1.4 uses "PBEWithMD5AndDES" and which is
223-
# very weak. It is essentially a password-based encryption key, hashed
224-
# with MD5 around 1K times and then encrypted with the weak DES algorithm
225-
# (56-bits) using ECB mode and an unspecified padding (it is
226-
# JCE provider specific, but most likely "NoPadding"). However, 2.0 uses
227-
# "AES/CBC/PKCSPadding". If you want to change these, change them here.
228201
# Warning: This property does not control the default reference implementation for
229202
# ESAPI 2.0 using JavaEncryptor. Also, this property will be dropped
230203
# in the future.
@@ -273,7 +246,6 @@ Encryptor.cipher_modes.additional_allowed=CBC,ECB
273246
# cipher transformation, otherwise this will be ignored after logging a
274247
# warning.
275248
#
276-
# NOTE: This is what applies BOTH ESAPI 1.4 and 2.0. See warning above about mixing!
277249
Encryptor.EncryptionKeyLength=128
278250
# Min key length - to support testing with 2TDEA
279251
Encryptor.MinEncryptionKeyLength=112

‎src/test/resources/esapi/ESAPI-DualValidatorFileChecker.properties‎

Lines changed: 0 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -63,12 +63,6 @@
6363
# get updated dynamically.
6464
#
6565
# Before using, be sure to update the MasterKey and MasterSalt as described below.
66-
# N.B.: If you had stored data that you have previously encrypted with ESAPI 1.4,
67-
# you *must* FIRST decrypt it using ESAPI 1.4 and then (if so desired)
68-
# re-encrypt it with ESAPI 2.0. If you fail to do this, you will NOT be
69-
# able to decrypt your data with ESAPI 2.0.
70-
#
71-
# YOU HAVE BEEN WARNED!!! More details are in the ESAPI 2.0 Release Notes.
7266
#
7367
#===========================================================================
7468
# ESAPI Configuration
@@ -158,21 +152,6 @@ Encoder.DefaultCodecList=HTMLEntityCodec,PercentCodec,JavaScriptCodec
158152
# unlimited strength policy files and install in the lib directory of your JRE/JDK.
159153
# See http://java.sun.com/javase/downloads/index.jsp for more information.
160154
#
161-
# Backward compatibility with ESAPI Java 1.4 is supported by the two deprecated API
162-
# methods, Encryptor.encrypt(String) and Encryptor.decrypt(String). However, whenever
163-
# possible, these methods should be avoided as they use ECB cipher mode, which in almost
164-
# all circumstances a poor choice because of it's weakness. CBC cipher mode is the default
165-
# for the new Encryptor encrypt / decrypt methods for ESAPI Java 2.0. In general, you
166-
# should only use this compatibility setting if you have persistent data encrypted with
167-
# version 1.4 and even then, you should ONLY set this compatibility mode UNTIL
168-
# you have decrypted all of your old encrypted data and then re-encrypted it with
169-
# ESAPI 2.0 using CBC mode. If you have some reason to mix the deprecated 1.4 mode
170-
# with the new 2.0 methods, make sure that you use the same cipher algorithm for both
171-
# (256-bit AES was the default for 1.4; 128-bit is the default for 2.0; see below for
172-
# more details.) Otherwise, you will have to use the new 2.0 encrypt / decrypt methods
173-
# where you can specify a SecretKey. (Note that if you are using the 256-bit AES,
174-
# that requires downloading the special jurisdiction policy files mentioned above.)
175-
#
176155
# ***** IMPORTANT: These are for JUnit testing. Test files may have been
177156
# encrypted using these values so do not change these or
178157
# those tests will fail. The version under
@@ -219,12 +198,6 @@ Encryptor.PreferredJCEProvider=
219198

220199
# AES is the most widely used and strongest encryption algorithm. This
221200
# should agree with your Encryptor.CipherTransformation property.
222-
# By default, ESAPI Java 1.4 uses "PBEWithMD5AndDES" and which is
223-
# very weak. It is essentially a password-based encryption key, hashed
224-
# with MD5 around 1K times and then encrypted with the weak DES algorithm
225-
# (56-bits) using ECB mode and an unspecified padding (it is
226-
# JCE provider specific, but most likely "NoPadding"). However, 2.0 uses
227-
# "AES/CBC/PKCSPadding". If you want to change these, change them here.
228201
# Warning: This property does not control the default reference implementation for
229202
# ESAPI 2.0 using JavaEncryptor. Also, this property will be dropped
230203
# in the future.
@@ -273,7 +246,6 @@ Encryptor.cipher_modes.additional_allowed=CBC,ECB
273246
# cipher transformation, otherwise this will be ignored after logging a
274247
# warning.
275248
#
276-
# NOTE: This is what applies BOTH ESAPI 1.4 and 2.0. See warning above about mixing!
277249
Encryptor.EncryptionKeyLength=128
278250

279251
# Min key length - to support testing with 2TDEA

‎src/test/resources/esapi/ESAPI-QuotedValidatorFileChecker.properties‎

Lines changed: 0 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -62,12 +62,6 @@
6262
# get updated dynamically.
6363
#
6464
# Before using, be sure to update the MasterKey and MasterSalt as described below.
65-
# N.B.: If you had stored data that you have previously encrypted with ESAPI 1.4,
66-
# you *must* FIRST decrypt it using ESAPI 1.4 and then (if so desired)
67-
# re-encrypt it with ESAPI 2.0. If you fail to do this, you will NOT be
68-
# able to decrypt your data with ESAPI 2.0.
69-
#
70-
# YOU HAVE BEEN WARNED!!! More details are in the ESAPI 2.0 Release Notes.
7165
#
7266
#===========================================================================
7367
# ESAPI Configuration
@@ -157,21 +151,6 @@ Encoder.DefaultCodecList=HTMLEntityCodec,PercentCodec,JavaScriptCodec
157151
# unlimited strength policy files and install in the lib directory of your JRE/JDK.
158152
# See http://java.sun.com/javase/downloads/index.jsp for more information.
159153
#
160-
# Backward compatibility with ESAPI Java 1.4 is supported by the two deprecated API
161-
# methods, Encryptor.encrypt(String) and Encryptor.decrypt(String). However, whenever
162-
# possible, these methods should be avoided as they use ECB cipher mode, which in almost
163-
# all circumstances a poor choice because of it's weakness. CBC cipher mode is the default
164-
# for the new Encryptor encrypt / decrypt methods for ESAPI Java 2.0. In general, you
165-
# should only use this compatibility setting if you have persistent data encrypted with
166-
# version 1.4 and even then, you should ONLY set this compatibility mode UNTIL
167-
# you have decrypted all of your old encrypted data and then re-encrypted it with
168-
# ESAPI 2.0 using CBC mode. If you have some reason to mix the deprecated 1.4 mode
169-
# with the new 2.0 methods, make sure that you use the same cipher algorithm for both
170-
# (256-bit AES was the default for 1.4; 128-bit is the default for 2.0; see below for
171-
# more details.) Otherwise, you will have to use the new 2.0 encrypt / decrypt methods
172-
# where you can specify a SecretKey. (Note that if you are using the 256-bit AES,
173-
# that requires downloading the special jurisdiction policy files mentioned above.)
174-
#
175154
# ***** IMPORTANT: These are for JUnit testing. Test files may have been
176155
# encrypted using these values so do not change these or
177156
# those tests will fail. The version under
@@ -218,12 +197,6 @@ Encryptor.PreferredJCEProvider=
218197

219198
# AES is the most widely used and strongest encryption algorithm. This
220199
# should agree with your Encryptor.CipherTransformation property.
221-
# By default, ESAPI Java 1.4 uses "PBEWithMD5AndDES" and which is
222-
# very weak. It is essentially a password-based encryption key, hashed
223-
# with MD5 around 1K times and then encrypted with the weak DES algorithm
224-
# (56-bits) using ECB mode and an unspecified padding (it is
225-
# JCE provider specific, but most likely "NoPadding"). However, 2.0 uses
226-
# "AES/CBC/PKCSPadding". If you want to change these, change them here.
227200
# Warning: This property does not control the default reference implementation for
228201
# ESAPI 2.0 using JavaEncryptor. Also, this property will be dropped
229202
# in the future.
@@ -272,7 +245,6 @@ Encryptor.cipher_modes.additional_allowed=CBC,ECB
272245
# cipher transformation, otherwise this will be ignored after logging a
273246
# warning.
274247
#
275-
# NOTE: This is what applies BOTH ESAPI 1.4 and 2.0. See warning above about mixing!
276248
Encryptor.EncryptionKeyLength=128
277249
# Min key length - to support testing with 2TDEA
278250
Encryptor.MinEncryptionKeyLength=112

‎src/test/resources/esapi/ESAPI-SingleValidatorFileChecker.properties‎

Lines changed: 0 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -62,12 +62,6 @@
6262
# get updated dynamically.
6363
#
6464
# Before using, be sure to update the MasterKey and MasterSalt as described below.
65-
# N.B.: If you had stored data that you have previously encrypted with ESAPI 1.4,
66-
# you *must* FIRST decrypt it using ESAPI 1.4 and then (if so desired)
67-
# re-encrypt it with ESAPI 2.0. If you fail to do this, you will NOT be
68-
# able to decrypt your data with ESAPI 2.0.
69-
#
70-
# YOU HAVE BEEN WARNED!!! More details are in the ESAPI 2.0 Release Notes.
7165
#
7266
#===========================================================================
7367
# ESAPI Configuration
@@ -157,21 +151,6 @@ Encoder.DefaultCodecList=HTMLEntityCodec,PercentCodec,JavaScriptCodec
157151
# unlimited strength policy files and install in the lib directory of your JRE/JDK.
158152
# See http://java.sun.com/javase/downloads/index.jsp for more information.
159153
#
160-
# Backward compatibility with ESAPI Java 1.4 is supported by the two deprecated API
161-
# methods, Encryptor.encrypt(String) and Encryptor.decrypt(String). However, whenever
162-
# possible, these methods should be avoided as they use ECB cipher mode, which in almost
163-
# all circumstances a poor choice because of it's weakness. CBC cipher mode is the default
164-
# for the new Encryptor encrypt / decrypt methods for ESAPI Java 2.0. In general, you
165-
# should only use this compatibility setting if you have persistent data encrypted with
166-
# version 1.4 and even then, you should ONLY set this compatibility mode UNTIL
167-
# you have decrypted all of your old encrypted data and then re-encrypted it with
168-
# ESAPI 2.0 using CBC mode. If you have some reason to mix the deprecated 1.4 mode
169-
# with the new 2.0 methods, make sure that you use the same cipher algorithm for both
170-
# (256-bit AES was the default for 1.4; 128-bit is the default for 2.0; see below for
171-
# more details.) Otherwise, you will have to use the new 2.0 encrypt / decrypt methods
172-
# where you can specify a SecretKey. (Note that if you are using the 256-bit AES,
173-
# that requires downloading the special jurisdiction policy files mentioned above.)
174-
#
175154
# ***** IMPORTANT: These are for JUnit testing. Test files may have been
176155
# encrypted using these values so do not change these or
177156
# those tests will fail. The version under
@@ -218,12 +197,6 @@ Encryptor.PreferredJCEProvider=
218197

219198
# AES is the most widely used and strongest encryption algorithm. This
220199
# should agree with your Encryptor.CipherTransformation property.
221-
# By default, ESAPI Java 1.4 uses "PBEWithMD5AndDES" and which is
222-
# very weak. It is essentially a password-based encryption key, hashed
223-
# with MD5 around 1K times and then encrypted with the weak DES algorithm
224-
# (56-bits) using ECB mode and an unspecified padding (it is
225-
# JCE provider specific, but most likely "NoPadding"). However, 2.0 uses
226-
# "AES/CBC/PKCSPadding". If you want to change these, change them here.
227200
# Warning: This property does not control the default reference implementation for
228201
# ESAPI 2.0 using JavaEncryptor. Also, this property will be dropped
229202
# in the future.
@@ -272,7 +245,6 @@ Encryptor.cipher_modes.additional_allowed=CBC,ECB
272245
# cipher transformation, otherwise this will be ignored after logging a
273246
# warning.
274247
#
275-
# NOTE: This is what applies BOTH ESAPI 1.4 and 2.0. See warning above about mixing!
276248
Encryptor.EncryptionKeyLength=128
277249
# Min key length - to support testing with 2TDEA
278250
Encryptor.MinEncryptionKeyLength=112

‎src/test/resources/esapi/ESAPI.properties‎

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -199,12 +199,6 @@ Encryptor.PreferredJCEProvider=
199199

200200
# AES is the most widely used and strongest encryption algorithm. This
201201
# should agree with your Encryptor.CipherTransformation property.
202-
# By default, ESAPI Java 1.4 uses "PBEWithMD5AndDES" and which is
203-
# very weak. It is essentially a password-based encryption key, hashed
204-
# with MD5 around 1K times and then encrypted with the weak DES algorithm
205-
# (56-bits) using ECB mode and an unspecified padding (it is
206-
# JCE provider specific, but most likely "NoPadding"). However, 2.0 uses
207-
# "AES/CBC/PKCSPadding". If you want to change these, change them here.
208202
# Warning: This property does not control the default reference implementation for
209203
# ESAPI 2.0 using JavaEncryptor. Also, this property will be dropped
210204
# in the future.

0 commit comments

Comments
 (0)