Default Secret Encryption Key - Sonatype Nexus Repository - Sonatype Community

Default Secret Encryption Key

post by ahmad.hashem on Oct 15, 2024

Default Secret Encryption Key

After upgrade Nexus sso from 3.72 to 3.73

I get Default Secret Encryption Key

Nexus was not configured with an encryption key and is using the Default key.

Is there a guide to fix that?

post by mpiggott on Oct 16, 2024

https://help.sonatype.com/en/re-encryption-in-nexus-repository.html

post by ahmad.hashem on Oct 17, 2024

Thanks for your response, I have read this Guide, But it is totally non-understandable to me.

post by alexey.stepanov on Oct 18, 2024

I think this instruction is for cloud installations.

post by ahmad.hashem on Oct 18, 2024

I have my own on-premise installation.

post by mpiggott on Oct 18, 2024

The instructions are for on-premise.

post by lemonsterfy on Oct 21, 2024

Method 1: Using the NEXUS_SECRETS_KEY_FILE Environment Variable

Step 1: Create the JSON Configuration File

  1. Create a file, e.g., /path/to/nexus.secrets.json, with the following content:

    {
         "active": "your-key-id",
         "keys": [
           {
             "id": "your-key-id",
             "key": "your-encryption-key"
           }
         ]
    }
    
    • Replace “your-key-id” with your desired key ID.
    • Replace “your-encryption-key” with your generated encryption key (e.g., a 32-byte Base64 encoded string).
  2. Secure the file:

    chmod 600 /path/to/nexus.secrets.json
    

Step 2: Configure Nexus Service File

  1. Edit the Nexus systemd service file (typically located at /etc/systemd/system/nexus.service). Add the following line in the [Service] section:
    [Service]
    Environment="NEXUS_SECRETS_KEY_FILE=/path/to/nexus.secrets.json"
    
    1. Reload systemd and restart Nexus:
    sudo systemctl daemon-reload
    sudo systemctl restart nexus
    

Step 3: Verify the Configuration

  1. Check Nexus startup logs for any errors or warnings related to the encryption key:
    sudo journalctl -u nexus
    
  2. Log in to the Nexus UI and verify that the previous warnings about using the default encryption key are no longer present.

Step 4: Update Encryption Settings via Web Interface

  1. Log in to the Nexus web interface using the admin account.
  2. Navigate to: System > API > Security Management: Secrets Encryption
  3. Update the configuration with the following JSON:
    {
         "secretKeyId": "your-key-id",
         "notifyEmail": "your-email@example.com"
    }
    
    • Replace “your-key-id” with the ID of the key you want to activate (the same ID specified in the JSON file).
    • Replace “your-email@example.com” with the email address to receive notifications.
  4. Execute the update to apply the new encryption settings.

Method 2: Using the nexus.secrets.file Property in nexus.properties

Step 1: Create the JSON Configuration File

  1. Create the secrets JSON file: As in Method 1, create a file, e.g., /path/to/nexus.secrets.json, with the same content as above.

  2. Secure the file:

    chmod 600 /path/to/nexus.secrets.json
    

Step 2: Edit nexus.properties

  1. Locate the nexus.properties file, typically found in the custom directory at /your-path/sonatype-work/nexus3/etc/nexus.properties.
  2. Add the following line to specify the secrets file location:
    nexus.secrets.file=/path/to/nexus.secrets.json
    

Step 3: Restart Nexus

After modifying nexus.properties, restart Nexus to apply the changes:

sudo systemctl restart nexus

Step 4: Verify the Configuration

  1. Check Nexus startup logs for any errors or warnings related to the encryption key:

    sudo journalctl -u nexus
    
  2. Log in to the Nexus UI and verify that the previous warnings about using the default encryption key are no longer present.

Step 5: Update Encryption Settings via Web Interface

  1. Log in to the Nexus web interface using the admin account.
  2. Navigate to: System > API > Security Management: Secrets Encryption
  3. Update the configuration with the following JSON:
    {
         "secretKeyId": "your-key-id",
         "notifyEmail": "your-email@example.com"
    }
    
    1. Execute the update to apply the new encryption settings.