Default Secret Encryption Key - Sonatype Nexus Repository - Sonatype Community
Default Secret Encryption Key
post by ahmad.hashem on Oct 15, 2024
Default Secret Encryption Key
After upgrade Nexus sso from 3.72 to 3.73
I get Default Secret Encryption Key
Nexus was not configured with an encryption key and is using the Default key.
Is there a guide to fix that?
post by mpiggott on Oct 16, 2024
https://help.sonatype.com/en/re-encryption-in-nexus-repository.html
post by ahmad.hashem on Oct 17, 2024
Thanks for your response, I have read this Guide, But it is totally non-understandable to me.
post by alexey.stepanov on Oct 18, 2024
I think this instruction is for cloud installations.
post by ahmad.hashem on Oct 18, 2024
I have my own on-premise installation.
post by mpiggott on Oct 18, 2024
The instructions are for on-premise.
post by lemonsterfy on Oct 21, 2024
Method 1: Using the NEXUS_SECRETS_KEY_FILE Environment Variable
Step 1: Create the JSON Configuration File
Create a file, e.g.,
/path/to/nexus.secrets.json, with the following content:{ "active": "your-key-id", "keys": [ { "id": "your-key-id", "key": "your-encryption-key" } ] }- Replace “your-key-id” with your desired key ID.
- Replace “your-encryption-key” with your generated encryption key (e.g., a 32-byte Base64 encoded string).
Secure the file:
chmod 600 /path/to/nexus.secrets.json
Step 2: Configure Nexus Service File
- Edit the Nexus systemd service file (typically located at
/etc/systemd/system/nexus.service). Add the following line in the[Service]section:[Service] Environment="NEXUS_SECRETS_KEY_FILE=/path/to/nexus.secrets.json"- Reload systemd and restart Nexus:
sudo systemctl daemon-reload sudo systemctl restart nexus
Step 3: Verify the Configuration
- Check Nexus startup logs for any errors or warnings related to the encryption key:
sudo journalctl -u nexus - Log in to the Nexus UI and verify that the previous warnings about using the default encryption key are no longer present.
Step 4: Update Encryption Settings via Web Interface
- Log in to the Nexus web interface using the admin account.
- Navigate to: System > API > Security Management: Secrets Encryption
- Update the configuration with the following JSON:
{ "secretKeyId": "your-key-id", "notifyEmail": "your-email@example.com" }- Replace “your-key-id” with the ID of the key you want to activate (the same ID specified in the JSON file).
- Replace “your-email@example.com” with the email address to receive notifications.
- Execute the update to apply the new encryption settings.
Method 2: Using the nexus.secrets.file Property in nexus.properties
Step 1: Create the JSON Configuration File
Create the secrets JSON file: As in Method 1, create a file, e.g.,
/path/to/nexus.secrets.json, with the same content as above.Secure the file:
chmod 600 /path/to/nexus.secrets.json
Step 2: Edit nexus.properties
- Locate the
nexus.propertiesfile, typically found in the custom directory at/your-path/sonatype-work/nexus3/etc/nexus.properties. - Add the following line to specify the secrets file location:
nexus.secrets.file=/path/to/nexus.secrets.json
Step 3: Restart Nexus
After modifying nexus.properties, restart Nexus to apply the changes:
sudo systemctl restart nexus
Step 4: Verify the Configuration
Check Nexus startup logs for any errors or warnings related to the encryption key:
sudo journalctl -u nexusLog in to the Nexus UI and verify that the previous warnings about using the default encryption key are no longer present.
Step 5: Update Encryption Settings via Web Interface
- Log in to the Nexus web interface using the admin account.
- Navigate to: System > API > Security Management: Secrets Encryption
- Update the configuration with the following JSON:
{ "secretKeyId": "your-key-id", "notifyEmail": "your-email@example.com" }- Execute the update to apply the new encryption settings.