HashPassword.java

/*
** Module   : HashPassword.java
** Abstract : A method and a utility that calculates and prints password hash
**
** Copyright (c) 2009-2023, Golden Code Development Corporation.
**
** -#- -I- --Date-- --JPRM-- ----------------Description----------------------
** 001 NVS 20090304   @41412 Created initial implementation.
** 002 NVS 20090521   @42420 This file is now the only encapsulation of the
**                           password hashing algorithm for all uses in P2J.
** 003 NVS 20090810   @43584 Integrated EncodePassword functionality as well.
**                           Now HashPassword can run in batch mode taking
**                           all passwords from the command line arguments and
**                           printing their hashes on stdout, one per line.
** 004 GBB 20230512          Logging methods replaced by CentralLogger/ConversionStatus.
*/ 
/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
** 
** Additional terms under GNU Affero GPL version 3 section 7:
** 
**   Under Section 7 of the GNU Affero GPL version 3, the following additional
**   terms apply to the works covered under the License.  These additional terms
**   are non-permissive additional terms allowed under Section 7 of the GNU
**   Affero GPL version 3 and may not be removed by you.
** 
**   0. Attribution Requirement.
** 
**     You must preserve all legal notices or author attributions in the covered
**     work or Appropriate Legal Notices displayed by works containing the covered
**     work.  You may not remove from the covered work any author or developer
**     credit already included within the covered work.
** 
**   1. No License To Use Trademarks.
** 
**     This license does not grant any license or rights to use the trademarks
**     Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
**     of Golden Code Development Corporation. You are not authorized to use the
**     name Golden Code, FWD, or the names of any author or contributor, for
**     publicity purposes without written authorization.
** 
**   2. No Misrepresentation of Affiliation.
** 
**     You may not represent yourself as Golden Code Development Corporation or FWD.
** 
**     You may not represent yourself for publicity purposes as associated with
**     Golden Code Development Corporation, FWD, or any author or contributor to
**     the covered work, without written authorization.
** 
**   3. No Misrepresentation of Source or Origin.
** 
**     You may not represent the covered work as solely your work.  All modified
**     versions of the covered work must be marked in a reasonable way to make it
**     clear that the modified work is not originating from Golden Code Development
**     Corporation or FWD.  All modified versions must contain the notices of
**     attribution required in this license.
*/

package com.goldencode.p2j.security;

import java.io.*;
import java.security.*;

import com.goldencode.p2j.directory.Base64;
import com.goldencode.p2j.util.logging.*;

/**
 * This class implements a password hashing public method and a command line
 * utility.
 */
public class HashPassword
{
   /** Logger */
   private static final CentralLogger LOG = CentralLogger.get(HashPassword.class);
   
   /**
    * Hashes string into a digest used as an internal password represenation.
    *
    * @param     plain
    *            plain text password
    *
    * @return    array of bytes representing the hashed string or 
    *            <code>null</code>, if SHA algorithm is unavailable.
    */
   public static byte[] hashPassword(String plain)
   {
      byte[] hash = null;
      
      try
      {
         MessageDigest md = MessageDigest.getInstance("SHA");
         hash = md.digest(plain.getBytes());
      }
      catch(NoSuchAlgorithmException e)
      {
         // nothing to do but return nothing
      }

      return hash;
   }
   
   /**
    * The command line entry point.
    * 
    * @param     args
    *            The array of command-line parameters. Not used here.
    */
   public static void main(String[] args)
   {
      // interactive versus batch
      boolean interactive = args.length == 0;
      
      // get the console if interactive
      Console cons = null;
      
      if (interactive)
      {
         cons = System.console();
      
         if (cons == null)
         {
            LOG.warning("Console not available");
            return;
         }
      }
      
      char[] passwd = null;
      char[] passw2 = null;
      int ndx = 0;
      
      again:
      while(true)
      {
         StringBuilder sb = new StringBuilder("");
            
         if (interactive)
         {
            // read the first copy 
            passwd = cons.readPassword("[%s]", "Enter  password:");
            passw2 = cons.readPassword("[%s]", "Verify password:");
   
            // compare two copies and convert nto a string
            for (int i = 0; i < passwd.length; i++)
            {
               if (passwd[i] != passw2[i])
               {
                  System.out.println("Passwords don't match. Retry");
                  continue again;
               }
               
               sb.append(passwd[i]);
            }
            
            java.util.Arrays.fill(passwd, ' ');
            java.util.Arrays.fill(passw2, ' ');
         }
         else
         {
            sb.append(args[ndx++]);
         }
         
         byte[] hash = hashPassword(sb.toString());
         
         // print the hash
         String hashs = Base64.byteArrayToBase64(hash);
         if (interactive)
         {
            System.out.print("Hash is: ");
         }
         System.out.println(hashs);

         if (interactive || ndx == args.length)
         {
            break;
         }
      }
   }
}