You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用securityUtility hash编码密码后无法打开KeyStore和TrustStore求助

问题修复方案

错误原因

你使用--encoding=hash生成的是单向哈希值,这种算法只能用来验证密码是否匹配,无法逆向解密出原始密码。而KeyStore/TrustStore需要获取原始密码来解锁密钥库文件,因此会抛出「哈希算法不支持解密操作」的异常。

解决步骤

  1. 生成可逆加密的密码
    放弃hash编码,使用Liberty支持的可逆加密方式(默认是AES)重新加密密码:

    # 默认使用AES加密
    ./target/liberty/wlp/bin/securityUtility encode
    

    执行命令后输入明文密码,会生成类似{aes}xxxxxxxxxxxx格式的加密串。
    也可以显式指定AES编码:

    ./target/liberty/wlp/bin/securityUtility encode --encoding=aes
    
  2. 替换配置文件中的密码
    将server.xml里KeyStore配置的{hash}xxx替换为新生成的{aes}xxx加密串:

    <keyStore id="myKeyStore" location="resources/key.p12" type="PKCS12" password="{aes}新生成的加密串"/>
    <keyStore id="myTrustStore" location="resources/trust.p12" type="PKCS12" password="{aes}新生成的加密串"/>
    
  3. 确认特性配置
    确保server.xml中已添加passwordUtilities-1.1特性(你已完成此步骤,无需重复操作):

    <featureManager>
        <feature>passwordUtilities-1.1</feature>
        <!-- 其他特性 -->
    </featureManager>
    

注意事项

  • {hash}编码仅适用于无需还原原始密码的场景,比如用户登录密码验证;
  • 对于KeyStore、数据源等需要获取原始密码的场景,必须使用可逆加密算法(如AES)。

内容的提问来源于stack exchange,提问作者Genna

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 02:25:04