无运行环境访问权限时,如何解密OIM数据库的usr_password列?
解密OIM数据库备份中usr_password列的离线方法
你手里的JKS密钥库、XLDATABASEKEY文件是解密的核心依赖,以下是无需OIM运行环境的离线解密步骤:
步骤1:从JKS中提取可用密钥
用JDK自带的keytool和开源工具openssl处理JKS文件,无需OIM环境:
- 先查看JKS中的密钥别名(默认OIM密钥别名通常为
oimkey,若不符需确认实际别名):keytool -list -keystore oim.jks - 导出密钥证书:
keytool -exportcert -alias oimkey -keystore oim.jks -file oim_cert.cer - 将DER格式证书转为PEM格式,方便后续处理:
openssl x509 -inform der -in oim_cert.cer -out oim_cert.pem
步骤2:解密XLDATABASEKEY获取根密钥
XLDATABASEKEY是加密数据库字段的根密钥,本身由JKS密钥加密,用纯JDK代码即可解密:
import java.io.FileInputStream; import java.nio.file.Files; import java.nio.file.Paths; import java.security.KeyStore; import java.security.PrivateKey; import javax.crypto.Cipher; public class DecryptXLDatabaseKey { public static void main(String[] args) throws Exception { String jksPath = "你的JKS文件路径"; String jksPassword = "JKS的访问密码"; String alias = "oimkey"; // 替换为实际密钥别名 String xldbKeyPath = "你的XLDATABASEKEY文件路径"; KeyStore ks = KeyStore.getInstance("JKS"); ks.load(new FileInputStream(jksPath), jksPassword.toCharArray()); PrivateKey privateKey = (PrivateKey) ks.getKey(alias, jksPassword.toCharArray()); Cipher cipher = Cipher.getInstance("RSA/ECB/PKCS1Padding"); cipher.init(Cipher.DECRYPT_MODE, privateKey); byte[] encryptedKey = Files.readAllBytes(Paths.get(xldbKeyPath)); byte[] decryptedKey = cipher.doFinal(encryptedKey); System.out.println("明文根密钥:" + new String(decryptedKey)); } }
编译运行这段代码,得到明文的根密钥(仅需JDK 8+环境,无需OIM依赖)。
步骤3:解密usr_password字段
OIM的usr_password字段是用根密钥通过AES(旧版本可能用3DES)加密后Base64编码的,用以下代码解密:
import javax.crypto.Cipher; import javax.crypto.spec.SecretKeySpec; import java.util.Base64; public class DecryptOIMPassword { public static void main(String[] args) throws Exception { String rootKey = "步骤2得到的明文根密钥"; String encryptedPassword = "数据库中usr_password的Base64值"; // 若为OIM旧版本,将算法改为"DESede/ECB/PKCS5Padding" SecretKeySpec secretKey = new SecretKeySpec(rootKey.getBytes(), "AES"); Cipher cipher = Cipher.getInstance("AES/ECB/PKCS5Padding"); cipher.init(Cipher.DECRYPT_MODE, secretKey); byte[] encryptedBytes = Base64.getDecoder().decode(encryptedPassword); byte[] decryptedBytes = cipher.doFinal(encryptedBytes); System.out.println("明文密码:" + new String(decryptedBytes)); } }
替换对应参数后编译运行,即可得到明文密码。
关键注意事项
- JKS的访问密码必须正确,否则整个流程无法推进
- 部分旧版OIM使用3DES算法,需对应调整代码中的加密算法参数
- 所有操作仅依赖JDK和openssl,无需任何OIM运行环境
内容的提问来源于stack exchange,提问作者Azim ali
相关产品推荐
相关产品推荐

