如何在Tomcat 9的context.xml中加密数据源密码?
加密Tomcat数据源密码的实现需求与问题
我们的应用需对context.xml中的数据源密码进行加密以满足安全审计要求,Tomcat FAQ提及的模糊安全方案无法满足要求,必须实现真正的加密机制。
当前context.xml中的数据源配置如下:
<Resource name="jdbc/OracleDataSource" auth="Container" type="javax.sql.DataSource" driverClassName="oracle.jdbc.OracleDriver" url="jdbc:oracle:thin:@ServerName:PORT/NAME" username="APP_USERNAME" password="APP_PASSWORD" testWhileIdle="true" testOnBorrow="true" testOnReturn="false" validationQuery="select 1 from dual" timeBetweenEvictionRunsMillis="5000" maxTotal="100" maxIdle="20" minIdle="10" maxWaitMillis="10000" initialSize="10" removeAbandonedTimeout="1800" removeAbandonedOnBorrow="true" removeAbandonedOnMaintenance="true" logAbandoned="true" minEvictableIdleTimeMillis="30000" />
应用代码已实现RC4解密逻辑,可将@RC4Encode@XXX,XXX,...格式的密文解密为明文密码,该逻辑已在其他凭证场景中正常使用。现在希望在context.xml中复用此逻辑处理数据源密码,但不知具体实现方式。
尝试使用BasicDataSourceFactory时出现ClassNotFoundException,且因无服务器catalina.properties及对应目录的访问权限,无法使用属性替换或外部XML实体方案。若能解决DataSourceFactory找不到的问题,可复制现有解密方法,通过自定义DataSourceFactory解密RC4加密密码后传入数据源配置,大致伪代码如下:
public class APPDataSourceFactory extends BasicDataSourceFactory { private String encrypted_pwd = "@RC4Encode@123,456,789,012,345"; public String decrypt_pwd(String encrypted_pwd, String key){ // 现有RC4解密步骤 return decrypted_pwd; } }
内容的提问来源于stack exchange,提问作者Rob
相关产品推荐
相关产品推荐

