Class OfficeEncryptionHandler


  • public class OfficeEncryptionHandler
    extends Object
    Removes office encryption from an .accdb database.

    The decryption itself is the read path, so this works for every scheme CryptCodecProvider can open, agile and the older ones alike. What this adds is page 0 and the SIDs.

    Page 0 is never encrypted and carries three things which have to go: the encoding key, which office uses as a per file salt, the password field, which holds the low byte of that key repeated, and the EncryptionInfo structure. The format version is left as it is, because ms access raises it when it writes agile and does not lower it again when the encryption is removed.

    Clearing the password field moves the key which masks every SID, so the SIDs follow, see SidRemasker. Leaving that field alone to avoid the work is not an option: ms access reads it as a database password and prompts for one.

    Author:
    James Ahlborn
    • Method Detail

      • removeEncryption

        public static void removeEncryption​(Path srcFile,
                                            Path dstFile,
                                            String password)
                                     throws IOException
        Copies the given encrypted database to the given destination, decrypted.
        Throws:
        IOException
      • addEncryption

        public static void addEncryption​(Path srcFile,
                                         Path dstFile,
                                         String password,
                                         AgileEncryptionConfig config)
                                  throws IOException
        Copies the given plain database to the given destination, encrypted with agile encryption under the given password.
        Throws:
        IOException