You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无运行环境访问权限时,如何解密OIM数据库的usr_password列?

解密OIM数据库备份中usr_password列的离线方法

你手里的JKS密钥库、XLDATABASEKEY文件是解密的核心依赖,以下是无需OIM运行环境的离线解密步骤:

步骤1:从JKS中提取可用密钥

用JDK自带的keytool和开源工具openssl处理JKS文件,无需OIM环境:

  • 先查看JKS中的密钥别名(默认OIM密钥别名通常为oimkey,若不符需确认实际别名):
    keytool -list -keystore oim.jks
    
  • 导出密钥证书:
    keytool -exportcert -alias oimkey -keystore oim.jks -file oim_cert.cer
    
  • 将DER格式证书转为PEM格式,方便后续处理:
    openssl x509 -inform der -in oim_cert.cer -out oim_cert.pem
    

步骤2:解密XLDATABASEKEY获取根密钥

XLDATABASEKEY是加密数据库字段的根密钥,本身由JKS密钥加密,用纯JDK代码即可解密:

import java.io.FileInputStream;
import java.nio.file.Files;
import java.nio.file.Paths;
import java.security.KeyStore;
import java.security.PrivateKey;
import javax.crypto.Cipher;

public class DecryptXLDatabaseKey {
    public static void main(String[] args) throws Exception {
        String jksPath = "你的JKS文件路径";
        String jksPassword = "JKS的访问密码";
        String alias = "oimkey"; // 替换为实际密钥别名
        String xldbKeyPath = "你的XLDATABASEKEY文件路径";

        KeyStore ks = KeyStore.getInstance("JKS");
        ks.load(new FileInputStream(jksPath), jksPassword.toCharArray());
        PrivateKey privateKey = (PrivateKey) ks.getKey(alias, jksPassword.toCharArray());

        Cipher cipher = Cipher.getInstance("RSA/ECB/PKCS1Padding");
        cipher.init(Cipher.DECRYPT_MODE, privateKey);

        byte[] encryptedKey = Files.readAllBytes(Paths.get(xldbKeyPath));
        byte[] decryptedKey = cipher.doFinal(encryptedKey);
        System.out.println("明文根密钥:" + new String(decryptedKey));
    }
}

编译运行这段代码,得到明文的根密钥(仅需JDK 8+环境,无需OIM依赖)。

步骤3:解密usr_password字段

OIM的usr_password字段是用根密钥通过AES(旧版本可能用3DES)加密后Base64编码的,用以下代码解密:

import javax.crypto.Cipher;
import javax.crypto.spec.SecretKeySpec;
import java.util.Base64;

public class DecryptOIMPassword {
    public static void main(String[] args) throws Exception {
        String rootKey = "步骤2得到的明文根密钥";
        String encryptedPassword = "数据库中usr_password的Base64值";
        
        // 若为OIM旧版本,将算法改为"DESede/ECB/PKCS5Padding"
        SecretKeySpec secretKey = new SecretKeySpec(rootKey.getBytes(), "AES");
        Cipher cipher = Cipher.getInstance("AES/ECB/PKCS5Padding");
        cipher.init(Cipher.DECRYPT_MODE, secretKey);

        byte[] encryptedBytes = Base64.getDecoder().decode(encryptedPassword);
        byte[] decryptedBytes = cipher.doFinal(encryptedBytes);
        System.out.println("明文密码:" + new String(decryptedBytes));
    }
}

替换对应参数后编译运行,即可得到明文密码。

关键注意事项

  • JKS的访问密码必须正确,否则整个流程无法推进
  • 部分旧版OIM使用3DES算法,需对应调整代码中的加密算法参数
  • 所有操作仅依赖JDK和openssl,无需任何OIM运行环境

内容的提问来源于stack exchange,提问作者Azim ali

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 00:01:08