Using Encrypted DataSource Password in JBoss AS7

Securing our Application Server resources is one of the most important administrative task. JBoss AS7 uses picketbox security implementations. In this example we will see how we can provide an Encrypted Password for our DataSources rather than using the ClearText Password. The picketbox provides us a class for encrypting the Cleartext passwords using class “”

BUT in earlier versions on JBoss the Class was available as part of a different package “” … So while using JBoss AS7 we must always make sure that we are using the right SecureIdentityLoginModule class as “”

In this demonstration we will be using JBoss AS7 ( jboss-as-7.1.0.Beta1 ) which can be downloaded from the following link:

Step1). Create a DataSource as following:

01 <subsystem xmlns="urn:jboss:domain:datasources:1.0">
02     <datasources>
03         <datasource jndi-name="java:jboss/datasources/ExampleDS" pool-name="H2DS" enabled="true">
04             <connection-url>
05                 jdbc:h2:mem:test;DB_CLOSE_DELAY=-1
06             </connection-url>
07             <driver>
08                 h2
09             </driver>
10             <security>
11                 <user-name>sa</user-name>
12                 <password>sa</password>
13             </security>
14         </datasource>
16         <!-- ************************************************* -->
17         <!-- We Added the below DataSource configuration Here -->
18         <datasource jndi-name="java:/MySqlDS" pool-name="MySqlDS_Pool" enabled="true" jta="false" use-ccm="false">
19             <connection-url>
20                 jdbc:mysql://localhost:3306/testDB
21             </connection-url>
22             <driver-class>
23                 com.mysql.jdbc.Driver
24             </driver-class>
25             <driver>
26                 mysql-connector-java-5.1.13-bin.jar
27             </driver>
28             <security>
29                 <security-domain>
30                     encrypted-ds
31                 </security-domain>
32             </security>
33         </datasource>
34         <!-- ************************************************* -->
36         <drivers>
37             <driver name="h2" module="com.h2database.h2">
38                 <xa-datasource-class>
39                     org.h2.jdbcx.JdbcDataSource
40                 </xa-datasource-class>
41             </driver>
42         </drivers>
43     </datasources>
44 </subsystem>

In above case as we are using “mysql-connector-java-5.1.13-bin.jar” JDBC Driver which is a JDBC 4 compliant Driver so we just placed this Jar file inside the “jboss-as-7.1.0.Beta1/standalone/deployments” directory before creating the DataSource.

In the above DataSource configuration you will notice that inside the security tags we have NOT provided the Username and password rather we are providing the security-domain name (encrypted-ds) which we are going to configure in our next steps.

For more information on installing JDBC Driver and creating DataSources you can refer to the following article:

The simplest thing what you can do is just create a DataSource through JBoss Console as mentioned in the above link and then edit the following section of your DataSource to use security-domain rather than user-name and password attributes.

1 <security>
2      <user-name>dbUserOne</user-name>
3      <password>PasswordXYZ</password>
4 </security>

Step2). Open a Shell Prompt and then set the CLASSPATH to point to the following JAR’s “picketbox-4.0.6.Beta1.jar” and “jboss-logging-3.1.0.CR2.jar” because these Jars are required to encrypt the clear text password.

1 [userone@localhost ~]$      export JBOSS_HOME=/home/userone/jboss-as-7.1.0.Beta1
2 .
3 [userone@localhost ~]$      export CLASSPATH=${JBOSS_HOME}/modules/org/picketbox/main/picketbox-4.0.6.Beta1.jar:${JBOSS_HOME}/modules/org/jboss/logging/main/jboss-logging-3.1.0.CR2.jar:$CLASSPATH
5 [userone@localhost ~]$      java PasswordXYZ
6 Encoded password: -5bbc51443039e029747687c1d9ec6a8d
7 .

NOTE: In above demo suppose our Database Poassword is “PasswordXYZ” so after running the above command we got the encrypted password as “-5bbc51443039e029747687c1d9ec6a8d”

Step3). Now We need to create a “security-domain” inside out “${JBOSS_HOME}/standalone/configuration/standalone-full.xml” file as following, By providing the above Encrypted Password:

1 <security-domain name="encrypted-ds" cache-type="default">
2     <authentication>
3         <login-module code="" flag="required">
4             <module-option name="username" value="dbUserOne"/>
5             <module-option name="password" value="-5bbc51443039e029747687c1d9ec6a8d"/>
6             <module-option name="managedConnectionFactoryName" value="jboss.jca:service=LocalTxCM,name=MySqlDS_Pool"/>
7         </login-module>
8     </authentication>
9 </security-domain>

Step4). That’s all now just restart your JBoss profile like following:

1 .
2 ./ -c standalone-full.xml
3 .

Testing JBossAS7 DataSource connections using CLI

Step5). Following are the JBoss CLI command which you can use to test your DataSource is working fine or not.
In Standalone mode:

1 [standalone@localhost:9999 /] /subsystem=datasources/data-source=MySqlDS_Pool:test-connection-in-pool
2 {
3     "outcome" => "success",
4     "result" => [true]
5 }

In Domain mode:

1 [domain@localhost:9999 /] /host=master/server=server-one/subsystem=datasources/data-source=MySqlDS_Pool:test-connection-in-pool
2 {
3     "outcome" => "success",
4     "result" => [true]
5 }

What if you enter a Wrong Encrypted password in your JBoss Configuration?

Then you will see following kind of exception in your .JBoss Console:

01 03:19:12,578 INFO  [] (MSC service thread 1-4) JBAS011907: Register module: Module "deployment.mysql-connector-java-5.1.13-bin.jar:main" from Service Module Loader
02 03:19:12,641 ERROR [$AS7DataSourceDeployer] (MSC service thread 1-2) Exception during createSubject()PB00024: Access Denied:Unauthenticated caller:null: java.lang.SecurityException: PB00024: Access Denied:Unauthenticated caller:null
03     at [picketbox-4.0.9.Final.jar:4.0.9.Final]
04     at org.jboss.jca.deployers.common.AbstractDsDeployer$ [ironjacamar-deployers-common-1.0.11.Final.jar:1.0.11.Final]
05     at org.jboss.jca.deployers.common.AbstractDsDeployer$ [ironjacamar-deployers-common-1.0.11.Final.jar:1.0.11.Final]
06     at Method) [rt.jar:1.7.0_05]
07     at org.jboss.jca.deployers.common.AbstractDsDeployer.createSubject( [ironjacamar-deployers-common-1.0.11.Final.jar:1.0.11.Final]
08     at org.jboss.jca.deployers.common.AbstractDsDeployer.deployDataSource( [ironjacamar-deployers-common-1.0.11.Final.jar:1.0.11.Final]
09     at org.jboss.jca.deployers.common.AbstractDsDeployer.createObjectsAndInjectValue( [ironjacamar-deployers-common-1.0.11.Final.jar:1.0.11.Final]
10     at$AS7DataSourceDeployer.deploy( [jboss-as-connector-7.1.2.Final.jar:7.1.2.Final]
11     at [jboss-as-connector-7.1.2.Final.jar:7.1.2.Final]
12     at org.jboss.msc.service.ServiceControllerImpl$StartTask.startService( [jboss-msc-1.0.2.GA.jar:1.0.2.GA]
13     at org.jboss.msc.service.ServiceControllerImpl$ [jboss-msc-1.0.2.GA.jar:1.0.2.GA]
14     at java.util.concurrent.ThreadPoolExecutor.runWorker( [rt.jar:1.7.0_05]
15     at java.util.concurrent.ThreadPoolExecutor$ [rt.jar:1.7.0_05]
16     at [rt.jar:1.7.0_05]


01 ERROR [org.jboss.jca.core.connectionmanager.pool.strategy.PoolBySubject] (management-handler-thread - 3) IJ000614: Exception during createSubject() PB00024: Access Denied:Unauthenticated caller:null: java.lang.SecurityException: PB00024: Access Denied:Unauthenticated caller:null
02     at [picketbox-4.0.9.Final.jar:4.0.9.Final]
03     at org.jboss.jca.core.connectionmanager.pool.strategy.PoolBySubject$ [ironjacamar-core-impl-1.0.11.Final.jar:1.0.11.Final]
04     at org.jboss.jca.core.connectionmanager.pool.strategy.PoolBySubject$ [ironjacamar-core-impl-1.0.11.Final.jar:1.0.11.Final]
05     at Method) [rt.jar:1.7.0_05]
06     at org.jboss.jca.core.connectionmanager.pool.strategy.PoolBySubject.createSubject( [ironjacamar-core-impl-1.0.11.Final.jar:1.0.11.Final]
07     at org.jboss.jca.core.connectionmanager.pool.strategy.PoolBySubject.testConnection( [ironjacamar-core-impl-1.0.11.Final.jar:1.0.11.Final]
08     at$TestConnectionInPool.invokeCommandOn( [jboss-as-connector-7.1.2.Final.jar:7.1.2.Final]
09     at$1.execute( [jboss-as-connector-7.1.2.Final.jar:7.1.2.Final]
10     at [jboss-as-controller-7.1.2.Final.jar:7.1.2.Final]
11     at [jboss-as-controller-7.1.2.Final.jar:7.1.2.Final]
12     at [jboss-as-controller-7.1.2.Final.jar:7.1.2.Final]
13     at [jboss-as-connector-7.1.2.Final.jar:7.1.2.Final]
14     at [jboss-as-controller-7.1.2.Final.jar:7.1.2.Final]
15     at [jboss-as-controller-7.1.2.Final.jar:7.1.2.Final]
16     at [jboss-as-controller-7.1.2.Final.jar:7.1.2.Final]
17     at$DefaultPrepareStepHandler.execute( [jboss-as-controller-7.1.2.Final.jar:7.1.2.Final]
18     at [jboss-as-controller-7.1.2.Final.jar:7.1.2.Final]
19     at [jboss-as-controller-7.1.2.Final.jar:7.1.2.Final]
20     at [jboss-as-controller-7.1.2.Final.jar:7.1.2.Final]
21     at [jboss-as-controller-7.1.2.Final.jar:7.1.2.Final]
22     at [jboss-as-controller-7.1.2.Final.jar:7.1.2.Final]
23     at$ExecuteRequestHandler.doExecute( [jboss-as-controller-7.1.2.Final.jar:7.1.2.Final]
24     at$ExecuteRequestHandler$1.execute( [jboss-as-controller-7.1.2.Final.jar:7.1.2.Final]
25     at$2$1.doExecute(
26     at$
27     at java.util.concurrent.ThreadPoolExecutor.runWorker( [rt.jar:1.7.0_05]
28     at java.util.concurrent.ThreadPoolExecutor$ [rt.jar:1.7.0_05]
29     at [rt.jar:1.7.0_05]
30     at [jboss-threads-2.0.0.GA.jar:2.0.0.GA]

And your CLI comman to test DataSource connections will fail like following:

1 [standalone@localhost:9999 /] /subsystem=datasources/data-source=MySqlDS_Pool:test-connection-in-pool
2 {
3     "outcome" => "failed",
4     "failure-description" => "JBAS010440: failed to invoke operation: JBAS010447: Connection is not valid",
5     "rolled-back" => true
6 }

MiddlewareMagic Team

