fix: only validate encryption key if HSM not active

This commit is contained in:
Daniel Hougaard
2025-10-22 14:47:59 +04:00
parent 9f8e99a7e9
commit f3396b63f6
+27 -26
View File
@@ -122,36 +122,37 @@ const cryptographyFactory = () => {
const appCfg = envCfg || getConfig(); const appCfg = envCfg || getConfig();
if (appCfg.ENCRYPTION_KEY) { const hsmStatus = await isHsmActiveAndEnabled({
// we need to validate that the ENCRYPTION_KEY is a base64 encoded 256-bit key hsmService,
kmsRootConfigDAL
});
// note(daniel): for some reason this resolves as true for some hex-encoded strings. // if the encryption strategy is software - user needs to provide an encryption key
if (!isBase64(appCfg.ENCRYPTION_KEY)) { // if the encryption strategy is null AND the hsm is not configured - user needs to provide an encryption key
throw new CryptographyError({ const needsEncryptionKey =
message: hsmStatus.rootKmsConfigEncryptionStrategy === RootKeyEncryptionStrategy.Software ||
"FIPS mode is enabled, but the ENCRYPTION_KEY environment variable is not a base64 encoded 256-bit key.\nYou can generate a 256-bit key using the following command: `openssl rand -base64 32`" (hsmStatus.rootKmsConfigEncryptionStrategy === null && !hsmStatus.isHsmConfigured);
});
}
if (bytesToBits(Buffer.from(appCfg.ENCRYPTION_KEY, "base64").length) !== 256) { // only perform encryption key validation if it's actually required.
throw new CryptographyError({ if (needsEncryptionKey) {
message: if (appCfg.ENCRYPTION_KEY) {
"FIPS mode is enabled, but the ENCRYPTION_KEY environment variable is not a 256-bit key.\nYou can generate a 256-bit key using the following command: `openssl rand -base64 32`" // we need to validate that the ENCRYPTION_KEY is a base64 encoded 256-bit key
});
}
} else {
const hsmStatus = await isHsmActiveAndEnabled({
hsmService,
kmsRootConfigDAL
});
// if the encryption strategy is software - user needs to provide an encryption key // note(daniel): for some reason this resolves as true for some hex-encoded strings.
// if the encryption strategy is null AND the hsm is not configured - user needs to provide an encryption key if (!isBase64(appCfg.ENCRYPTION_KEY)) {
const needsEncryptionKey = throw new CryptographyError({
hsmStatus.rootKmsConfigEncryptionStrategy === RootKeyEncryptionStrategy.Software || message:
(hsmStatus.rootKmsConfigEncryptionStrategy === null && !hsmStatus.isHsmConfigured); "FIPS mode is enabled, but the ENCRYPTION_KEY environment variable is not a base64 encoded 256-bit key.\nYou can generate a 256-bit key using the following command: `openssl rand -base64 32`"
});
}
if (needsEncryptionKey) { if (bytesToBits(Buffer.from(appCfg.ENCRYPTION_KEY, "base64").length) !== 256) {
throw new CryptographyError({
message:
"FIPS mode is enabled, but the ENCRYPTION_KEY environment variable is not a 256-bit key.\nYou can generate a 256-bit key using the following command: `openssl rand -base64 32`"
});
}
} else {
throw new CryptographyError({ throw new CryptographyError({
message: message:
"FIPS mode is enabled, but the ENCRYPTION_KEY environment variable is not set.\nYou can generate a 256-bit key using the following command: `openssl rand -base64 32`" "FIPS mode is enabled, but the ENCRYPTION_KEY environment variable is not set.\nYou can generate a 256-bit key using the following command: `openssl rand -base64 32`"