You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Shell脚本中安全加解密文本及属性文件加密密码

Secure Shell Script Workflow for Encrypted Password Storage & Automated Auth

Great question! Let’s break this down into a practical, secure workflow that meets both your needs: encrypting/decrypting text in shell scripts, and automating password retrieval from a property file without exposing plaintext or requiring manual input.

Part 1: Implementing Encryption/Decryption with OpenSSL

We’ll use OpenSSL AES-256-CBC (a robust, widely supported encryption standard) paired with PBKDF2 key derivation to add extra resistance against brute-force attacks.

Step 1: Generate a Secure Encryption Key

First, create a random 256-bit key and store it in a restricted-access location (only the user running your script should have read/write access):

# Generate a 32-byte (256-bit) random key
openssl rand -hex 32 > /opt/secure/service_encryption.key
# Lock down permissions (critical for security!)
chmod 600 /opt/secure/service_encryption.key

Step 2: Encrypt Your Plaintext Password

Run this command to encrypt your password and get a base64-encoded ciphertext (ready to paste into your property file):

# Replace "your_actual_password" with the password you want to encrypt
echo -n "your_actual_password" | openssl enc -aes-256-cbc -salt -pbkdf2 -iter 100000 -pass file:/opt/secure/service_encryption.key | base64

You’ll get a long string like U2FsdGVkX1+... — copy this for your property file.

Step 3: Verify Decryption (Optional)

To confirm everything works, decrypt the ciphertext back to plaintext:

# Replace "your_encrypted_ciphertext" with the string from Step 2
echo "your_encrypted_ciphertext" | base64 -d | openssl enc -aes-256-cbc -d -salt -pbkdf2 -iter 100000 -pass file:/opt/secure/service_encryption.key

Part 2: Automated Workflow with Property File

Now let’s build a script that reads the encrypted password from a property file, decrypts it securely, and uses it for service authentication.

1. Create Your Property File

Make a file named service.properties with your encrypted password (replace the value with your ciphertext from Step 2):

# service.properties
service.username=my_service_user
service.password=U2FsdGVkX1+...[your encrypted ciphertext]...

Lock down this file too:

chmod 600 service.properties

2. Write the Shell Script

This script will handle reading, decrypting, and using the password without exposing plaintext. Adjust the authentication step to match your service (example uses a curl request):

#!/bin/bash

# Define paths (keep these out of public repos!)
KEY_FILE="/opt/secure/service_encryption.key"
PROPERTY_FILE="./service.properties"

# Validate key file security first
if [ ! -f "$KEY_FILE" ] || [ "$(stat -c %a "$KEY_FILE")" != "600" ]; then
    echo "Error: Encryption key missing or permissions are insecure!"
    exit 1
fi

# Extract encrypted password from property file
ENCRYPTED_PW=$(grep -E '^service.password=' "$PROPERTY_FILE" | cut -d'=' -f2)

# Decrypt password (captured into a variable, no console output)
DECRYPTED_PW=$(echo "$ENCRYPTED_PW" | base64 -d | openssl enc -aes-256-cbc -d -salt -pbkdf2 -iter 100000 -pass file:"$KEY_FILE")

# Use the decrypted password for authentication (example: curl request)
curl -u "$(grep -E '^service.username=' "$PROPERTY_FILE" | cut -d'=' -f2):$DECRYPTED_PW" https://your-service-api.com/auth

# Clear the decrypted password from memory after use
unset DECRYPTED_PW

Set secure permissions for the script:

chmod 700 auth_script.sh

Critical Security Best Practices

  • Never hardcode keys or plaintext passwords in scripts or version control systems.
  • Restrict all sensitive files: Key files, property files, and scripts should only be accessible to the user running the automation.
  • Avoid printing decrypted passwords: Capture them into variables instead of echoing to stdout.
  • Use strong key derivation: The -pbkdf2 -iter 100000 flags make brute-force attacks far more computationally expensive.
  • Rotate keys periodically: Generate new keys and re-encrypt passwords to minimize risk if keys are ever compromised.

内容的提问来源于stack exchange,提问作者Jugi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 04:09:13