From 94d029f2d786ff6a25a13a7b4c0c5d0f4b6573a3 Mon Sep 17 00:00:00 2001 From: YYTVicky <61596169+YYTVicky@users.noreply.github.com> Date: Thu, 5 Mar 2020 23:36:48 -0500 Subject: [PATCH] Update BouncyCastleAesBytesEncryptorEquivalencyTest.java --- .../encrypt/BouncyCastleAesBytesEncryptorEquivalencyTest.java | 1 + 1 file changed, 1 insertion(+) diff --git a/crypto/src/test/java/org/springframework/security/crypto/encrypt/BouncyCastleAesBytesEncryptorEquivalencyTest.java b/crypto/src/test/java/org/springframework/security/crypto/encrypt/BouncyCastleAesBytesEncryptorEquivalencyTest.java index 664b45051ba..548b3791af0 100644 --- a/crypto/src/test/java/org/springframework/security/crypto/encrypt/BouncyCastleAesBytesEncryptorEquivalencyTest.java +++ b/crypto/src/test/java/org/springframework/security/crypto/encrypt/BouncyCastleAesBytesEncryptorEquivalencyTest.java @@ -38,6 +38,7 @@ public class BouncyCastleAesBytesEncryptorEquivalencyTest { public void setup() { // generate random password, salt, and test data password = UUID.randomUUID().toString(); + /** insecure salt byte, recommend 64 or larger than 64*/ byte[] saltBytes = new byte[16]; secureRandom.nextBytes(saltBytes); salt = new String(Hex.encode(saltBytes));