Encrypt/Decrypt Columns
Posted in 2011
Topics: General Discussion
Hi all, I use Informix in my application and I want to encrypt columns. For encrypting I use Jasypt and Hibernate, for decrypting I have to use SQL. I proved to encrypt columns with algorithms AES and TDES, then I tried decrypting them with functions DECRYPT_CHAR() and DECRYPT_BINARY() but I got the following error. Error: The encrypted data is wrong or corrupted. SQLState: IX000 ErrorCode: -26005 Algorithm TDES was used PBEWithMD5AndTripleDES and algorithm AES was used PBEWITHSHA256AND128BITAES-CBC-BC. Any suggestion??? Thank you in advance.
you may need use both SQL function to encrypt and decrypt. the SQL encryption functions store some special information in the encrypted data, the SQL decrypt function will not recognize other encryption format.
On 26/01/2011 20:56, DCHARLINE DCHARLINE wrote: > Hi all, > > I use Informix in my application and I want to encrypt columns. For encrypting > I use Jasypt and Hibernate, for decrypting I have to use SQL. I proved to > encrypt columns with algorithms AES and TDES, then I tried decrypting them > with functions DECRYPT_CHAR() and DECRYPT_BINARY() but I got the following > error. > > Error: The encrypted data is wrong or corrupted. > > SQLState: IX000 > > ErrorCode: -26005 > > Algorithm TDES was used PBEWithMD5AndTripleDES and algorithm AES was used > PBEWITHSHA256AND128BITAES-CBC-BC. > > Any suggestion??? Use SQL to encrypt? -- Cheers, Obnoxio The Clown http://obotheclown.blogspot.com I will now proceed to pleasure myself with this fish.
Mostly repeating what others said, but a bit more explanation of why what you tried does not work. On Wed, Jan 26, 2011 at 12:56, DCHARLINE DCHARLINE <dcharline9@gmail.com>wrote: > I use Informix in my application and I want to encrypt columns. For > encrypting > I use Jasypt and Hibernate, for decrypting I have to use SQL. I proved to > encrypt columns with algorithms AES and TDES, then I tried decrypting them > with functions DECRYPT_CHAR() and DECRYPT_BINARY() but I got the following > error. > The format of the data generated by ENCRYPT_AES() is not simply the output of applying AES with the given password to the given data. There is control information and other material in there - such as the random IV, and the optional hint. All this allows IDS to tell when it has valid encrypted data to decode. Your chances of reproducing it outside the server are approximately nil - certainly, simply using any old AES or 3-DES algorithm is going to go nowhere. Error: The encrypted data is wrong or corrupted. > > SQLState: IX000 > > ErrorCode: -26005 > > Algorithm TDES was used PBEWithMD5AndTripleDES and algorithm AES was used > PBEWITHSHA256AND128BITAES-CBC-BC. > > Any suggestion??? > As others have said: use ENCRYPT_AES() to encrypt the data, and DECRYPT_CHAR() or DECRYPT_BINARY() to decrypt it. You might legitimately ask "can we have functions encrypt_aes() and so on in the client?" At the moment, there are no plans to provide them, mainly because there has not been customer demand for them. -- Jonathan Leffler <jonathan.leffler@gmail.com> #include <disclaimer.h> Guardian of DBD::Informix - v2008.0513 - http://dbi.perl.org "Blessed are we who can laugh at ourselves, for we shall never cease to be amused." --20cf30433ed2dc64a2049aced37b