Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
How to encrypt passwords for LiveSite 7.1 conf files?
Frederik
I created the following as a support case... thought I'd share the question already, and the answer when it's in.
--------
I recently did an installation of TS, LSDS, LSCS 7.1 for a 'test lab'
I noticed that several LiveSite (or SitePublisher) conf files contain encrypted user passwords (e.g. database or opendeploy users). I found no documentation about this encryption.
Below are 3 files (example) that have such encrypted passwords after the fresh install
$IW_HOME/local/config/lib/content_center/livesite_customer_src/etc/conf/livesite_customer/database.properties
$LSDS_HOME/runtime/web/WEB-INF/conf/livesite_customer/database.properties
$LSCS_HOME/runtime/webapps/lscs/WEB-INF/classes/lscs-conf.properties
My question is: how do I encrypt passwords for inclusion in these conf files.
For example if one of the database passwords changes and I need to update the conf...
Find more posts tagged with
Comments
catorarn
you need to use the following tool:
\interwoven\OpenDeploy\OpenDeployNG\bin>iwodpasscoder.bat iwodpasscoder - Encode a string. Usage: iwodpasscoder
\interwoven\OpenDeploy\OpenDeployNG\bin>iwodpasscoder.bat !nterw0ven
IW50ZXJ3MHZlbg===
then put this string in there like enc(W50ZXJ3MHZlbg===)
it does not matter that you use the opendeploy tool for ts or ls config files, that should work for all the products as it is using the same java class for all encoding in 71
Rick Poulin
I've had better luck using the encryptpassword utility in <lscsrt-home>/install/bin (for use in LSCSRT's lscs-conf.properties -- the OD one didn't work).
Frederik
I forgot to post back the answer I got from support.
This is what they told me (after several exchanges).
-----------------------------------------------------------------
(1) SitePublisher
to encrypt password for use in
$IW_HOME/local/config/lib/content_center/livesite_customer_src/etc/conf/livesite_customer/database.properties
use command line:
$IW_HOME/local/config/lib/content_center/livesite_customer_src/build.sh encrypt "-Dpw=password"
(2) LSCS
to encrypt password for use in
$LSCS_HOME/runtime/webapps/lscs/WEB-INF/classes/lscs-conf.properties
use command line:
$LSCS_HOME/install/bin/encryptpassword.sh << EOF
password
EOF
(3) LSDS
to encrypt password for use in
$LSDS_HOME/runtime/web/WEB-INF/conf/livesite_customer/database.properties
no tool available
the *only* way forward is to synchronize the key (passphrase) files of LSDS and SitePublisher, and then use the same command as for SitePublisher.
---------------------------------
mind you, I did not try (1) and (3) myself. By the time I finally had an answer from support, I had already written my own little java program based on the java code behind (2).
LOL, study of (2) also showed me how to decrypt the encrypted passwords. So, uhm, it's not an unbreakable encryption, but it's better than plaintext passwords nonetheless
PS: it's noteworthy that each execution of these encryption utils provide different encrypted outputs on every execution, even on the same cleartext password.
GanttChart.PNG
RonaldV
To add to the 2) answer:
the help-text/hint in the database.properties file about how to generate a encrypted password is thus FALSE!. Frederiks answer is the correct one.
HeMan10
Ronald,
Not sure which version of TeamSite you tried this on. But on 7.3.1, hint in database.properties works for us. However, we had to do it on the runtime as well as authoring for it to work.