You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Node.js实现MariaDB静态加密所需的OpenSSL SHA1密钥文件加密

Node.js实现MariaDB静态加密所需的SHA1密钥文件加密

Got it, let's get this sorted for you! You're looking to replace your existing MD5 encryption logic with SHA1 (the algorithm MariaDB requires for encrypting its keys.txt file) in Node.js, since you need to spin up MariaDB instances programmatically.

First off, you don't need a third-party gulp plugin for this—Node.js has a built-in crypto module that can perfectly replicate the SHA1 digest behavior of OpenSSL, which is exactly what MariaDB uses. Here's how to adjust your code:

Step 1: Replace MD5 with SHA1 using Node.js Crypto

Your existing MD5 function can be swapped out for a SHA1 equivalent with just a small tweak. Here's the full implementation, including file handling for your keys.txt:

const crypto = require('crypto');
const fs = require('fs').promises;

// Generate SHA1 hash (matches OpenSSL's `openssl dgst -sha1` output)
function generateSHA1Hash(data) {
  return crypto.createHash('sha1')
    .update(data)
    .digest('hex'); // Use 'hex' for human-readable hash, or omit for binary Buffer
}

// Read keys.txt and generate its SHA1 hash (as MariaDB expects)
async function processMariaDBKeyFile(filePath) {
  try {
    // Read the raw content of keys.txt
    const keyFileContent = await fs.readFile(filePath, 'utf8');
    // Generate SHA1 hash (adjust digest format if MariaDB needs binary/base64)
    const sha1Hash = generateSHA1Hash(keyFileContent);
    
    // If MariaDB requires binary hash (matches `openssl dgst -sha1 -binary`):
    // const sha1Binary = crypto.createHash('sha1').update(keyFileContent).digest();
    // If you need base64-encoded binary hash:
    // const sha1Base64 = sha1Binary.toString('base64');

    console.log('SHA1 hash for MariaDB keys.txt:', sha1Hash);
    return sha1Hash;
  } catch (error) {
    console.error('Failed to process key file:', error);
    throw error;
  }
}

// Example usage: process your keys.txt file
processMariaDBKeyFile('./keys.txt')
  .then(hash => {
    // Use this hash in your MariaDB instance setup for encryption at rest
  })
  .catch(err => process.exit(1));

Key Notes:

  • Matching OpenSSL Behavior: This code produces the exact same SHA1 output as running openssl dgst -sha1 keys.txt in your terminal when using the hex digest format. If MariaDB expects a binary hash (from openssl dgst -sha1 -binary), just use digest() without arguments to get a Buffer, then convert to base64 if needed.
  • No External Dependencies: Ditching the gulp plugin for Node's built-in crypto keeps your code lighter and avoids potential compatibility issues.
  • Drop-in Replacement: You can directly swap your old md5() function with generateSHA1Hash() wherever you were using it before, as the logic flow is identical—only the algorithm changes.

内容的提问来源于stack exchange,提问作者Jason Suttles

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 11:10:54