当前位置: 首页 > news >正文

【jceks】使用keytool和hadoop credential生成和解析jceks文件(无密码storepass)

build.gradle文件:

plugins {id 'org.jetbrains.kotlin.jvm' version '1.9.23'
}group = 'com.xxx.test'
version = '1.0-SNAPSHOT'repositories {mavenCentral()
}dependencies {implementation("org.apache.hadoop:hadoop-common:3.0.0")testImplementation 'org.jetbrains.kotlin:kotlin-test'
}test {useJUnitPlatform()
}
kotlin {jvmToolchain(8)
}

koltin语言编写。
ranger中的org.apache.ranger.credentialapi.CredentialReader工具类:

import org.apache.commons.lang3.StringUtils
import org.apache.hadoop.conf.Configuration
import org.apache.hadoop.security.alias.CredentialProvider.CredentialEntry
import org.apache.hadoop.security.alias.CredentialProviderFactory
import org.apache.hadoop.security.alias.JavaKeyStoreProvider
import java.util.*object CredentialReader {fun getDecryptedString(CrendentialProviderPath: String?, alias: String?, storeType: String?): String? {var CrendentialProviderPath = CrendentialProviderPathvar alias = aliasvar credential: String? = nulltry {if (CrendentialProviderPath == null || alias == null) {return null}var pass: CharArray? = nullval conf = Configuration()var crendentialProviderPrefixJceks = JavaKeyStoreProvider.SCHEME_NAME + "://file"val crendentialProviderPrefixLocalJceks = "localjceks://file"crendentialProviderPrefixJceks = crendentialProviderPrefixJceks.lowercase(Locale.getDefault())var crendentialProviderPrefixBcfks = "bcfks" + "://file"var crendentialProviderPrefixLocalBcfks = "localbcfks" + "://file"crendentialProviderPrefixBcfks = crendentialProviderPrefixBcfks.lowercase(Locale.getDefault())crendentialProviderPrefixLocalBcfks = crendentialProviderPrefixLocalBcfks.lowercase(Locale.getDefault())CrendentialProviderPath = CrendentialProviderPath.trim { it <= ' ' }alias = alias.trim { it <= ' ' }if (CrendentialProviderPath.lowercase(Locale.getDefault()).startsWith(crendentialProviderPrefixJceks) ||CrendentialProviderPath.lowercase(Locale.getDefault()).startsWith(crendentialProviderPrefixLocalJceks) ||CrendentialProviderPath.lowercase(Locale.getDefault()).startsWith(crendentialProviderPrefixBcfks) ||CrendentialProviderPath.lowercase(Locale.getDefault()).startsWith(crendentialProviderPrefixLocalBcfks)) {conf[CredentialProviderFactory.CREDENTIAL_PROVIDER_PATH] = CrendentialProviderPath} else {if (CrendentialProviderPath.startsWith("/")) {if (StringUtils.equalsIgnoreCase(storeType, "bcfks")) {conf[CredentialProviderFactory.CREDENTIAL_PROVIDER_PATH] = CrendentialProviderPath} else {conf[CredentialProviderFactory.CREDENTIAL_PROVIDER_PATH] =JavaKeyStoreProvider.SCHEME_NAME + "://file" + CrendentialProviderPath}} else {conf[CredentialProviderFactory.CREDENTIAL_PROVIDER_PATH] =JavaKeyStoreProvider.SCHEME_NAME + "://file/" + CrendentialProviderPath}}val providers = CredentialProviderFactory.getProviders(conf)var aliasesList: List<String?> = ArrayList()var credEntry: CredentialEntry? = nullfor (provider in providers) {//System.out.println("Credential Provider :" + provider);aliasesList = provider.aliasesif (aliasesList != null && aliasesList.contains(alias.lowercase(Locale.getDefault()))) {credEntry = nullcredEntry = provider.getCredentialEntry(alias.lowercase(Locale.getDefault()))pass = credEntry.credentialif (pass != null && pass.size > 0) {credential = String(pass)break}}}} catch (ex: Exception) {ex.printStackTrace()credential = null}return credential}
}

测试案例:

import org.junit.jupiter.api.Test
class CredentialReaderTest {val storeType = "jceks"@Testfun testDecrypted() {var path: String = "D:\\projects\\CredientialReader\\src\\test\\resources\\rangeradmin.jceks"path=path.replace("\\","/")val alias: String = "unixauthtruststorealias"val cred = CredentialReader.getDecryptedString(path, alias, storeType)println(cred) // success: somepassword}/*** method: 1, using `keytool` command!* [root@ranger conf]# keytool -importpass -alias ranger -storetype jceks -keystore tmp.jceks* Enter keystore password:* Re-enter new password:* Enter the password to be stored:* Re-enter password:* Enter key password for <ranger>*         (RETURN if same as keystore password):** [root@ranger conf]# keytool -list -v -storetype jceks -keystore tmp.jceks* Enter keystore password:* Keystore type: JCEKS* Keystore provider: SunJCE** Your keystore contains 1 entry** Alias name: ranger* Creation date: Apr 28, 2025* Entry type: SecretKeyEntry*/@Testfun testDecryptedTmp() {// failed : java.io.IOException: Keystore was tampered with, or password was incorrectvar path: String = "D:\\projects\\CredientialReader\\src\\test\\resources\\tmp.jceks"path=path.replace("\\","/")val alias: String = "ranger"val cred = CredentialReader.getDecryptedString(path, alias, storeType)println(cred)}/*** method: 2, using `hadoop credential` command* hadoop credential create -help* hadoop credential create ranger  -value 999 -provider localjceks:///home/someone/hdp.jceks* hdfs hdfs -copyToLocal /home/someone/hdp.jceks .* Note: "localjceks://file" is fixed,"/home/someone/hdp.jceks" is real path* hadoop credential create ranger  -value 999 -provider localjceks://file/home/someone/hdp.jceks* keytool -list -v -storetype jceks -keystore hdp.jceks* 999*/@Testfun testDecryptedHdp() {// success: 999var path: String = "D:\\projects\\CredientialReader\\src\\test\\resources\\hdp.jceks"path=path.replace("\\","/")val alias: String = "ranger"val cred = CredentialReader.getDecryptedString(path, alias, storeType)println(cred)}
}

使用keytool必须指定storepass,即jceks文件的密码。使用hadoop credential create命令生成的jceks的密码是NONE,就是没有密码。

相关文章:

  • Unity AI-使用Ollama本地大语言模型运行框架运行本地Deepseek等模型实现聊天对话(一)
  • 马井堂-大语言模型对教学的应用分析
  • 网络基础概念:从菜鸟到入门
  • 面试算法高频08-动态规划-03
  • 新环境注册为Jupyter 内核
  • Uniapp:vite.config.js全局配置
  • 可解释人工智能(XAI):让机器决策透明化
  • AI - LangChain - 介绍(1)
  • 成员方法的详细说明(结合Oracle官方文档)
  • 9.5/Q1,GBD数据库最新高分文章解读
  • Cursor
  • JVM 内存分配策略
  • spring cloud 服务注册与发现(Service registration and discovery)
  • 常见算法的总结与实现思路
  • Flutter 学习之旅 之 flutter 作为 module ,在 Android 的界面中嵌入Flutter界面功能的简单整理
  • 研究:大模型输出一致性:确定性与随机性的场景化平衡
  • 【Spark入门】Spark架构解析:组件与运行机制深度剖析
  • IP SSL证书常见问题:快速实现HTTPS加密
  • 【前端】【面试】如何实现图片渐进式加载?有几种方法
  • 根据模板语法生成和导出Word文档的工具类
  • 习近平在上海考察时强调,加快建成具有全球影响力的科技创新高地
  • “自己生病却让别人吃药”——抹黑中国经济解决不了美国自身问题
  • 夜读丨怀念那个写信的年代
  • 商务部:4月份以来的出口总体延续平稳增长态势
  • 五一假期“热潮”来袭,计划南下的小伙伴注意了
  • 因高颜值走红的女通缉犯出狱后当主播自称“改邪归正”,账号已被封