HashPassword.java
/*
** Module : HashPassword.java
** Abstract : A method and a utility that calculates and prints password hash
**
** Copyright (c) 2009-2023, Golden Code Development Corporation.
**
** -#- -I- --Date-- --JPRM-- ----------------Description----------------------
** 001 NVS 20090304 @41412 Created initial implementation.
** 002 NVS 20090521 @42420 This file is now the only encapsulation of the
** password hashing algorithm for all uses in P2J.
** 003 NVS 20090810 @43584 Integrated EncodePassword functionality as well.
** Now HashPassword can run in batch mode taking
** all passwords from the command line arguments and
** printing their hashes on stdout, one per line.
** 004 GBB 20230512 Logging methods replaced by CentralLogger/ConversionStatus.
*/
/*
** This program is free software: you can redistribute it and/or modify
** it under the terms of the GNU Affero General Public License as
** published by the Free Software Foundation, either version 3 of the
** License, or (at your option) any later version.
**
** This program is distributed in the hope that it will be useful,
** but WITHOUT ANY WARRANTY; without even the implied warranty of
** MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
** GNU Affero General Public License for more details.
**
** You may find a copy of the GNU Affero GPL version 3 at the following
** location: https://www.gnu.org/licenses/agpl-3.0.en.html
**
** Additional terms under GNU Affero GPL version 3 section 7:
**
** Under Section 7 of the GNU Affero GPL version 3, the following additional
** terms apply to the works covered under the License. These additional terms
** are non-permissive additional terms allowed under Section 7 of the GNU
** Affero GPL version 3 and may not be removed by you.
**
** 0. Attribution Requirement.
**
** You must preserve all legal notices or author attributions in the covered
** work or Appropriate Legal Notices displayed by works containing the covered
** work. You may not remove from the covered work any author or developer
** credit already included within the covered work.
**
** 1. No License To Use Trademarks.
**
** This license does not grant any license or rights to use the trademarks
** Golden Code, FWD, any Golden Code or FWD logo, or any other trademarks
** of Golden Code Development Corporation. You are not authorized to use the
** name Golden Code, FWD, or the names of any author or contributor, for
** publicity purposes without written authorization.
**
** 2. No Misrepresentation of Affiliation.
**
** You may not represent yourself as Golden Code Development Corporation or FWD.
**
** You may not represent yourself for publicity purposes as associated with
** Golden Code Development Corporation, FWD, or any author or contributor to
** the covered work, without written authorization.
**
** 3. No Misrepresentation of Source or Origin.
**
** You may not represent the covered work as solely your work. All modified
** versions of the covered work must be marked in a reasonable way to make it
** clear that the modified work is not originating from Golden Code Development
** Corporation or FWD. All modified versions must contain the notices of
** attribution required in this license.
*/
package com.goldencode.p2j.security;
import java.io.*;
import java.security.*;
import com.goldencode.p2j.directory.Base64;
import com.goldencode.p2j.util.logging.*;
/**
* This class implements a password hashing public method and a command line
* utility.
*/
public class HashPassword
{
/** Logger */
private static final CentralLogger LOG = CentralLogger.get(HashPassword.class);
/**
* Hashes string into a digest used as an internal password represenation.
*
* @param plain
* plain text password
*
* @return array of bytes representing the hashed string or
* <code>null</code>, if SHA algorithm is unavailable.
*/
public static byte[] hashPassword(String plain)
{
byte[] hash = null;
try
{
MessageDigest md = MessageDigest.getInstance("SHA");
hash = md.digest(plain.getBytes());
}
catch(NoSuchAlgorithmException e)
{
// nothing to do but return nothing
}
return hash;
}
/**
* The command line entry point.
*
* @param args
* The array of command-line parameters. Not used here.
*/
public static void main(String[] args)
{
// interactive versus batch
boolean interactive = args.length == 0;
// get the console if interactive
Console cons = null;
if (interactive)
{
cons = System.console();
if (cons == null)
{
LOG.warning("Console not available");
return;
}
}
char[] passwd = null;
char[] passw2 = null;
int ndx = 0;
again:
while(true)
{
StringBuilder sb = new StringBuilder("");
if (interactive)
{
// read the first copy
passwd = cons.readPassword("[%s]", "Enter password:");
passw2 = cons.readPassword("[%s]", "Verify password:");
// compare two copies and convert nto a string
for (int i = 0; i < passwd.length; i++)
{
if (passwd[i] != passw2[i])
{
System.out.println("Passwords don't match. Retry");
continue again;
}
sb.append(passwd[i]);
}
java.util.Arrays.fill(passwd, ' ');
java.util.Arrays.fill(passw2, ' ');
}
else
{
sb.append(args[ndx++]);
}
byte[] hash = hashPassword(sb.toString());
// print the hash
String hashs = Base64.byteArrayToBase64(hash);
if (interactive)
{
System.out.print("Hash is: ");
}
System.out.println(hashs);
if (interactive || ndx == args.length)
{
break;
}
}
}
}