Class EncryptionUtil


  • public class EncryptionUtil
    extends Object
    Adds and removes the encryption on a database. Reading an encrypted database needs CryptCodecProvider instead, and the jet database password, which is a different feature, is PasswordUtil.

    Every operation rewrites the whole file, so each takes a path rather than an open Database. The work builds a separate file and replaces the original only once that file is complete, so an interrupted operation leaves the original database as it was. The in place forms give the database a new identity on disk, which drops any hard link to it, and the database must not be in use.

    Jet encoding is what ms access called "Encode/Decode Database" and removed after access 2003. It applies to .mdb files, it has no password, and its key is stored in the file, so it stops only a reader which does not know about it. A current ms access opens an encoded database and cannot add or remove the encoding.

    Only jet 4 can be altered. Adding or removing the encoding rewrites the database, and jackcess does not write jet 3. An encoded jet 3 database still reads through CryptCodecProvider, which needs no change to the file.

    Jet encoding and the jet database password are independent, and this class leaves the password alone in both directions. To have both, call PasswordUtil as well, in either order.

    Author:
    James Ahlborn
    • Method Detail

      • addOfficeAgileEncryption

        public static void addOfficeAgileEncryption​(Path dbFile,
                                                    String password)
                                             throws IOException
        Encrypts the given .accdb database with agile encryption, replacing the file with the result. Agile is what a current ms access writes, and AgileEncryptionConfig.OFFICE_2010 is the profile it chooses.
        Parameters:
        dbFile - the plain database, not in use
        password - the password to encrypt it with, not empty
        Throws:
        IllegalStateException - if it is already encrypted
        IOException
      • addOfficeAgileEncryption

        public static void addOfficeAgileEncryption​(Path dbFile,
                                                    String password,
                                                    AgileEncryptionConfig config)
                                             throws IOException
        Encrypts the given .accdb database with agile encryption under the given algorithms, replacing the file with the result.
        Throws:
        IOException
      • addOfficeAgileEncryption

        public static void addOfficeAgileEncryption​(Path srcFile,
                                                    Path dstFile,
                                                    String password)
                                             throws IOException
        Writes an agile encrypted copy of the given .accdb database, leaving the source alone.
        Throws:
        IOException
      • addOfficeAgileEncryption

        public static void addOfficeAgileEncryption​(Path srcFile,
                                                    Path dstFile,
                                                    String password,
                                                    AgileEncryptionConfig config)
                                             throws IOException
        Writes a copy of the given .accdb database encrypted under the given algorithms, leaving the source alone.
        Throws:
        IOException
      • removeOfficeEncryption

        public static void removeOfficeEncryption​(Path dbFile,
                                                  String password)
                                           throws IOException
        Removes the encryption from the given .accdb database, replacing the file with the result.

        Every scheme CryptCodecProvider can read is supported, which is agile and the older ones alike. Extensible encryption is the exception, because it delegates to an external provider and cannot be read at all.

        The format version is left as it is. Ms access raises it when it writes agile encryption and does not lower it again when the encryption is removed, so a decrypted database keeps the raised version.

        Parameters:
        dbFile - the encrypted database, not in use
        password - the password it was encrypted with
        Throws:
        IllegalStateException - if it is not encrypted
        InvalidCredentialsException - if the password is wrong
        IOException
      • removeOfficeEncryption

        public static void removeOfficeEncryption​(Path srcFile,
                                                  Path dstFile,
                                                  String password)
                                           throws IOException
        Writes a decrypted copy of the given .accdb database, leaving the source alone.
        Parameters:
        srcFile - the encrypted database
        dstFile - where to write it, overwritten if it exists
        password - the password the source was encrypted with
        Throws:
        IllegalStateException - if the source is not encrypted
        InvalidCredentialsException - if the password is wrong
        IOException
      • addJetEncoding

        public static void addJetEncoding​(Path dbFile)
                                   throws IOException
        Adds jet encoding to the given database, under a freshly generated key, replacing the file with the result.
        Parameters:
        dbFile - the jet 4 database to encode, not in use
        Throws:
        IllegalStateException - if it is already encoded
        IOException
      • addJetEncoding

        public static void addJetEncoding​(Path srcFile,
                                          Path dstFile)
                                   throws IOException
        Writes an encoded copy of the given database, under a freshly generated key, leaving the source alone.
        Parameters:
        srcFile - the jet 4 database to encode
        dstFile - where to write it, overwritten if it exists
        Throws:
        IllegalStateException - if the source is already encoded
        IOException
      • removeJetEncoding

        public static void removeJetEncoding​(Path dbFile)
                                      throws IOException
        Removes the jet encoding from the given database, replacing the file with the result.
        Parameters:
        dbFile - the encoded jet 4 database, not in use
        Throws:
        IllegalStateException - if it is not encoded
        IOException
      • removeJetEncoding

        public static void removeJetEncoding​(Path srcFile,
                                             Path dstFile)
                                      throws IOException
        Writes a plain copy of the given encoded database, leaving the source alone.
        Parameters:
        srcFile - the encoded jet 4 database
        dstFile - where to write it, overwritten if it exists
        Throws:
        IllegalStateException - if the source is not encoded
        IOException