Browse Source

Update BouncyCastleAesBytesEncryptorEquivalencyTest.java

YYTVicky 5 years ago
parent
commit
d9f7422c2c

+ 1 - 0
crypto/src/test/java/org/springframework/security/crypto/encrypt/BouncyCastleAesBytesEncryptorEquivalencyTest.java

@@ -38,6 +38,7 @@ public class BouncyCastleAesBytesEncryptorEquivalencyTest {
 	public void setup() {
 	public void setup() {
 		// generate random password, salt, and test data
 		// generate random password, salt, and test data
 		password = UUID.randomUUID().toString();
 		password = UUID.randomUUID().toString();
+		/** insecure salt byte, recommend 64 or larger than 64*/
 		byte[] saltBytes = new byte[16];
 		byte[] saltBytes = new byte[16];
 		secureRandom.nextBytes(saltBytes);
 		secureRandom.nextBytes(saltBytes);
 		salt = new String(Hex.encode(saltBytes));
 		salt = new String(Hex.encode(saltBytes));