From 910593af514df28b4fac862e201e6c8ecafc6cb8 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bastien=20Cl=C3=A9ment?= Date: Mon, 22 Dec 2025 13:31:43 +0100 Subject: [PATCH] storage: fix algorithm label for 256-bit V2 encryption keys When generating 256-bit encryption keys in the version 2 (JWK) format, the algorithm was incorrectly labeled as 192-bit in the output JSON. This change ensures the label correctly reflects the 256-bit size. Resolves: #160004 Release note (bug fix): Fixed a bug where 256-bit encryption keys generated in the V2 (JWK) format were incorrectly labeled as 192-bit. Epic: None --- pkg/storage/enginepb/key_registry.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkg/storage/enginepb/key_registry.go b/pkg/storage/enginepb/key_registry.go index 05b51f0b1d11..97643cea0b47 100644 --- a/pkg/storage/enginepb/key_registry.go +++ b/pkg/storage/enginepb/key_registry.go @@ -22,7 +22,7 @@ func (e EncryptionType) JWKAlgorithm() (string, error) { case EncryptionType_AES_192_CTR_V2: return "cockroach-aes-192-ctr-v2", nil case EncryptionType_AES_256_CTR_V2: - return "cockroach-aes-192-ctr-v2", nil + return "cockroach-aes-256-ctr-v2", nil } return "", fmt.Errorf("unknown EncryptionType %d", e) }