如何在Shell脚本中安全加解密文本及属性文件加密密码
Great question! Let’s break this down into a practical, secure workflow that meets both your needs: encrypting/decrypting text in shell scripts, and automating password retrieval from a property file without exposing plaintext or requiring manual input.
Part 1: Implementing Encryption/Decryption with OpenSSL
We’ll use OpenSSL AES-256-CBC (a robust, widely supported encryption standard) paired with PBKDF2 key derivation to add extra resistance against brute-force attacks.
Step 1: Generate a Secure Encryption Key
First, create a random 256-bit key and store it in a restricted-access location (only the user running your script should have read/write access):
# Generate a 32-byte (256-bit) random key openssl rand -hex 32 > /opt/secure/service_encryption.key # Lock down permissions (critical for security!) chmod 600 /opt/secure/service_encryption.key
Step 2: Encrypt Your Plaintext Password
Run this command to encrypt your password and get a base64-encoded ciphertext (ready to paste into your property file):
# Replace "your_actual_password" with the password you want to encrypt echo -n "your_actual_password" | openssl enc -aes-256-cbc -salt -pbkdf2 -iter 100000 -pass file:/opt/secure/service_encryption.key | base64
You’ll get a long string like U2FsdGVkX1+... — copy this for your property file.
Step 3: Verify Decryption (Optional)
To confirm everything works, decrypt the ciphertext back to plaintext:
# Replace "your_encrypted_ciphertext" with the string from Step 2 echo "your_encrypted_ciphertext" | base64 -d | openssl enc -aes-256-cbc -d -salt -pbkdf2 -iter 100000 -pass file:/opt/secure/service_encryption.key
Part 2: Automated Workflow with Property File
Now let’s build a script that reads the encrypted password from a property file, decrypts it securely, and uses it for service authentication.
1. Create Your Property File
Make a file named service.properties with your encrypted password (replace the value with your ciphertext from Step 2):
# service.properties service.username=my_service_user service.password=U2FsdGVkX1+...[your encrypted ciphertext]...
Lock down this file too:
chmod 600 service.properties
2. Write the Shell Script
This script will handle reading, decrypting, and using the password without exposing plaintext. Adjust the authentication step to match your service (example uses a curl request):
#!/bin/bash # Define paths (keep these out of public repos!) KEY_FILE="/opt/secure/service_encryption.key" PROPERTY_FILE="./service.properties" # Validate key file security first if [ ! -f "$KEY_FILE" ] || [ "$(stat -c %a "$KEY_FILE")" != "600" ]; then echo "Error: Encryption key missing or permissions are insecure!" exit 1 fi # Extract encrypted password from property file ENCRYPTED_PW=$(grep -E '^service.password=' "$PROPERTY_FILE" | cut -d'=' -f2) # Decrypt password (captured into a variable, no console output) DECRYPTED_PW=$(echo "$ENCRYPTED_PW" | base64 -d | openssl enc -aes-256-cbc -d -salt -pbkdf2 -iter 100000 -pass file:"$KEY_FILE") # Use the decrypted password for authentication (example: curl request) curl -u "$(grep -E '^service.username=' "$PROPERTY_FILE" | cut -d'=' -f2):$DECRYPTED_PW" https://your-service-api.com/auth # Clear the decrypted password from memory after use unset DECRYPTED_PW
Set secure permissions for the script:
chmod 700 auth_script.sh
Critical Security Best Practices
- Never hardcode keys or plaintext passwords in scripts or version control systems.
- Restrict all sensitive files: Key files, property files, and scripts should only be accessible to the user running the automation.
- Avoid printing decrypted passwords: Capture them into variables instead of echoing to stdout.
- Use strong key derivation: The
-pbkdf2 -iter 100000flags make brute-force attacks far more computationally expensive. - Rotate keys periodically: Generate new keys and re-encrypt passwords to minimize risk if keys are ever compromised.
内容的提问来源于stack exchange,提问作者Jugi

