Details
-
Bug
-
Status: Closed
-
Minor
-
Resolution: Fixed
-
10.5.3.0
-
Windows XP SP3 / JRE 1.5 / Derby 10.5.3.0 embedded.
-
Normal
-
Security
Description
The documentation @ http://db.apache.org/derby/docs/10.5/devguide/tdevdvlp40140.html
states that
"If the algorithm that was used when the database was created is not the default algorithm, you must also specify the encryptionAlgorithm attribute"
yet when I gave the wrong value of "DES/CBC/NoPadding", having created the database with "DESede", it booted without a problem. I was concerned that it might not have actually encrypted with the correct algorithm, given this Java bug:
http://forums.sun.com/thread.jspa?threadID=5129170&start=15
I was concerned that it might not use strong (>128 bit) encryption. Other people may be similarly concerned about what the documentation seems to say, given the behavior of the code. I think that statement in quotes should be removed entirely, and one stating something to the effect of
"Just supply the bootPassword or encryptionKey attributes to boot the database."
Should replace it.
Attachments
Issue Links
- relates to
-
DERBY-1721 DOCS - Remove duplicate information in Dev Guide re: Encryption
- Closed