Fork me on GitHub

Jackcess Encrypt

Jackcess Encrypt is an extension library for the Jackcess project which implements support for some forms of Microsoft Access and Microsoft Money encryption. Jackcess Encrypt is licensed under the Apache License (as of version 2.1.0).

This project is separate from the main Jackcess project for two main reasons:

  • The encryption support requires an additional library (Bouncy Castle). Making this support separate from the main Jackcess library allows users to avoid including unnecessary libraries.
  • Sourceforge previously had restrictions on the distribution of software which used encryption. Keeping this support in a separate project allowed the main Jackcess library to be distributed more freely.

Java 11+ Support (2026-09-12)

Jackcess Encrypt now requires Java 11+ as of the 5.0.0 release. All third party dependencies have been updated to the latest versions and some legacy dependencies have been dropped.

Java 9+ Compatibility (2021-01-20)

While Jackcess Encrypt still only requires Java 8+, as of the 4.0.0 release it now includes an Automatic-Module-Name of com.healthmarketscience.jackcess.crypt in its manifest. This allows it to safely be used in the module path for Java 9+ projects. These changes correspond with the changes in Jackess 4.x.

As a consequence of supporting Java 9+ modules, the classes in this project needed to be moved to a new package in order to avoid the "split module" problem. The primary classes in this project are now in the com.healthmarketscience.jackcess.crypt package. This is a breaking change with respect to the 3.x release series.

Brand New License! (2015-04-16)

In order to match the License changes made in Jackcess 2.1.0, the Jackcess Encrypt project has been relicensed under the Apache License, Version 2.0 (Jackcess Encrypt versions 2.1.0 and higher).

Sample code

This project's encryption support can be utilized by providing a CryptCodecProvider when opening an Access Database.

  • Open a Database with normal Jet file encoding:
    Database db = new DatabaseBuilder(myDbFile)
      .setCodecProvider(new CryptCodecProvider())
      .open();
  • Open a Database with an encoding which requires a password to decode:
    Database db = new DatabaseBuilder(myDbFile)
      .setCodecProvider(new CryptCodecProvider("MyDbPassword"))
      .open();

The encryption itself can be added and removed using EncryptionUtil, and the Jet database password using PasswordUtil. These operations rewrite the entire database file, so they take a file path and the database must not be in use. The result is built in a separate file and put in place only once it is complete, so an interrupted operation leaves the original database as it was.

  • Encrypt an accdb file, replacing it with the encrypted version:
    EncryptionUtil.addOfficeAgileEncryption(myDbFile, "MyDbPassword");
  • Encrypt an accdb file using the stronger algorithms which Access 2013 writes, leaving the source file alone:
    EncryptionUtil.addOfficeAgileEncryption(
        myDbFile, myEncryptedDbFile, "MyDbPassword",
        AgileEncryptionConfig.OFFICE_2013);
  • Remove the encryption from an accdb file:
    EncryptionUtil.removeOfficeEncryption(myDbFile, "MyDbPassword");
  • Add or remove normal Jet file encoding on a Jet 4 mdb file:
    EncryptionUtil.addJetEncoding(myDbFile);
    
    EncryptionUtil.removeJetEncoding(myDbFile);
  • Set or remove the database password on a Jet 4 mdb file. This is a separate feature from the file encoding above, and the two can be used together:
    PasswordUtil.setDatabasePassword(myDbFile, "MyDbPassword");
    
    PasswordUtil.removeDatabasePassword(myDbFile);