[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fl2bbCI81RgkaBdQyOY9XIpAWpK5KNYIay5QufQG7OhY":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},679,"Where are the database connection passwords stored in VMware Workspace ONE Access, and how are they encrypted?","The plaintext password for the database is in \u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fdb.pwd. The encrypted password is in \u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fruntime-config.properties under `secure.datastore.jdbc.password`. Decryption requires the keys in \u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fconfigkeystore.pass and configkeystore.bcfks. The admin password is encrypted and stored in the database's PasswordInformation table, using AES encryption with a UUID-based salt. This encryption approach is similar to what you'll find in [Password Manager Pro Vulnerability Debugging Environment Setup](\u002Fnews\u002Fpassword-manager-pro-vulnerability-debugging-environment-setup).","\u003Cp>The plaintext password for the database is in \u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fdb.pwd. The encrypted password is in \u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fruntime-config.properties under `secure.datastore.jdbc.password`. Decryption requires the keys in \u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fconfigkeystore.pass and configkeystore.bcfks. The admin password is encrypted and stored in the database&#39;s PasswordInformation table, using AES encryption with a UUID-based salt. This encryption approach is similar to what you&#39;ll find in [Password Manager Pro Vulnerability Debugging Environment Setup](\u002Fnews\u002Fpassword-manager-pro-vulnerability-debugging-environment-setup).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fvmware-workspace-one-access-vulnerability-debugging-environment-setup\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","where-are-the-database-connection-passwords-stored-in-vmware-workspace-one-acces-1777482359699","database password, encryption, configkeystore, db.pwd, runtime-config.properties, AES",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},168,"VMware Workspace ONE Access Vulnerability Debugging Environment Setup","vmware-workspace-one-access-vulnerability-debugging-environment-setup","Step-by-step guide to set up VMware Workspace ONE Access vulnerability debugging environment, including OVA installation, SSH setup, and remote debugging configuration.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article details the process of setting up a VMware Workspace ONE Access vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>VMware Workspace ONE Access Installation\u003C\u002Fli>\u003Cli>VMware Workspace ONE Access Vulnerability Debugging Environment Configuration\u003C\u002Fli>\u003Cli>Common Knowledge\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 VMware Workspace ONE Access Installation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference Materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.vmware.com\u002Fen\u002FVMware-Workspace-ONE-Access\u002F20.01\u002Fworkspace_one_access_install.pdf\u003C\u002Fp>\u003Ch3>1. Download the OVA File\u003C\u002Fh3>\u003Cp>Download page:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fcustomerconnect.vmware.com\u002Fdownloads\u002Fsearch?query=workspace%20one%20access\u003C\u002Fp>\u003Cp>Registration is required before downloading, then select the desired version to download\u003C\u002Fp>\u003Cp>Download page for VMware Workspace ONE Access 21.08.0.1: https:\u002F\u002Fcustomerconnect.vmware.com\u002Fdownloads\u002Fdetails?downloadGroup=WS1A_ONPREM_210801&amp;productId=1269\u003C\u002Fp>\u003Cp>Download file identity-manager-21.08.0.1-19010796_OVF10.ova\u003C\u002Fp>\u003Ch3>2. Installation\u003C\u002Fh3>\u003Ch4>(1) Import the OVA file in VMware Workstation\u003C\u002Fh4>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>VMware Workstation version must be greater than 14, otherwise an error will occur indicating inability to import\u003C\u002Fp>\u003Cp>Set the Host Name on the installation page. If DHCP is configured, other options do not need to be set. My configuration uses a static IP, configured as shown in the image below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017291780_0_a1ffbd9eed.jpeg\">\u003C\u002Fp>\u003Cp>After the OVA file import is complete, it will automatically power on for initialization. After initialization is complete, it will appear as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017322087_1_a354d3d868.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Configuration\u003C\u002Fh4>\u003Cp>Modify the local hosts file to point 192.168.1.11 to workspaceone.test.com\u003C\u002Fp>\u003Cp>Access the configuration page at https:\u002F\u002Fworkspaceone.test.com:8443\u003C\u002Fp>\u003Cp>Set passwords for admin, root, and sshuser users; passwords must include uppercase letters, lowercase letters, numbers, and special characters\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>My test results show that the password length must be set to 14, otherwise root and sshuser users cannot log in\u003C\u002Fp>\u003Cp>In my test environment, the password is set to Password@12345, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017371211_2_850096d6b1.jpeg\">\u003C\u002Fp>\u003Cp>Set up the database; for ease of environment setup, select Internal Database here\u003C\u002Fp>\u003Cp>Wait for the installation to complete, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017395296_3_6919fa737b.jpeg\">\u003C\u002Fp>\u003Ch3>3. Enable remote SSH login for the root user\u003C\u002Fh3>\u003Cp>To log in to VMware Workspace ONE Access and modify the system configuration file, there are two login methods:\u003C\u002Fp>\u003Ch4>(1) Log in directly as the root user in the virtual machine\u003C\u002Fh4>\u003Cp>Select Login, enter root and the password Password@12345\u003C\u002Fp>\u003Ch4>(2) Log in via SSH as the sshuser user\u003C\u002Fh4>\u003Cp>After logging in, switch to the root user\u003C\u002Fp>\u003Cp>After switching to the root user, execute the following commands in sequence:\u003C\u002Fp>\u003Cul>\u003Cli>vi \u002Fetc\u002Fssh\u002Fsshd_config\u003C\u002Fli>\u003Cli>Change PermitRootLogin from no to yes\u003C\u002Fli>\u003Cli>systemctl restart sshd\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Enable remote debugging function\u003C\u002Fh3>\u003Cp>Modify the file: \u002Fopt\u002Fvmware\u002Fhorizon\u002Fworkspace\u002Fbin\u002Fsetenv.sh\u003C\u002Fp>\u003Cp>Modify the JVM_OPTS parameter, add: -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8000\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017440225_4_c68d49328e.jpeg\">\u003C\u002Fp>\u003Cp>Restart the system\u003C\u002Fp>\u003Cp>Open the firewall: iptables -P INPUT ACCEPT &amp;&amp; iptables -P OUTPUT ACCEPT\u003C\u002Fp>\u003Cp>Set remote debugging parameters in IDEA, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017466562_5_14c23726f6.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For the complete configuration method of IDEA, please refer to the previous article 'Setting Up Zimbra Vulnerability Debugging Environment'\u003C\u002Fp>\u003Ch2>0x03 Common Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Common Commands\u003C\u002Fh3>\u003Cp>Check system service status: chkconfig --list\u003C\u002Fp>\u003Cp>Check all service status: systemctl status\u003C\u002Fp>\u003Cp>Check IP address: ip addr show\u003C\u002Fp>\u003Cp>Check Host Name: hostname\u003C\u002Fp>\u003Cp>Log path: \u002Fopt\u002Fvmware\u002Fhorizon\u002Fworkspace\u002Flogs\u002F\u003C\u002Fp>\u003Ch3>2. Check System Version\u003C\u002Fh3>\u003Cp>Requires root privileges to execute command: vamicli version --appliance\u003C\u002Fp>\u003Cp>Implementation details for checking system version:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#!\u002Fusr\u002Fbin\u002Fenv python2\u003Cbr>import sys\u003Cbr>sys.path.append(\"\u002Fopt\u002Fvmware\u002Flib\u002Fpython\u002Fsite-packages\u002F\")\u003Cbr>import pywbem\u003Cbr>def getCIMConnection (url, namespace):\u003Cbr>    cred = {}\u003Cbr>    cred ['cert_file'] = '\u002Fopt\u002Fvmware\u002Fetc\u002Fsfcb\u002Fclient.pem'\u003Cbr>    cred ['key_file'] = '\u002Fopt\u002Fvmware\u002Fetc\u002Fsfcb\u002Ffile.pem'\u003Cbr>    cliconn = pywbem.WBEMConnection (url, None, namespace, cred)\u003Cbr>    return cliconn\u003Cbr>\u003Cbr>def showVersion():\u003Cbr>  try:\u003Cbr>    cliconn = getCIMConnection ('https:\u002F\u002Flocalhost:5489', 'root\u002Fcimv2')\u003Cbr>    esis = cliconn.EnumerateInstances ('VAMI_ElementSoftwareIdentity')\u003Cbr>  except:\u003Cbr>    print('error')\u003Cbr>    return\u003Cbr>  for esi in esis:\u003Cbr>    ess = esi ['ElementSoftwareStatus']\u003Cbr>    if (ess == [2, 6]):\u003Cbr>      inst = cliconn.GetInstance (esi['Antecedent'])\u003Cbr>      print ('Version - ' + inst ['VersionString'])\u003Cbr>      print ('Description - ' + inst ['Description'])\u003Cbr>showVersion()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Root privileges are required because accessing the files \u002Fopt\u002Fvmware\u002Fetc\u002Fsfcb\u002Fclient.pem and \u002Fopt\u002Fvmware\u002Fetc\u002Fsfcb\u002Ffile.pem requires root permissions.\u003C\u002Fp>\u003Ch3>3. Database Connection Password\u003C\u002Fh3>\u003Cp>The plaintext password for connecting to the database is located at: \u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fdb.pwd\u003C\u002Fp>\u003Cp>The encrypted password for connecting to the database is stored in the file \u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fruntime-config.properties. Example file content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>datastore.jdbc.url=jdbc:postgresql:\u002F\u002Flocalhost\u002Fsaas?stringtype=unspecified\u003Cbr>datastore.jdbc.userName=horizon\u003Cbr>secure.datastore.jdbc.password=BAACs8MW1xyMe7\u002F8ONd2QwtG3mw37wF1\u002F1pQ6D09xXqf56ncfRtCun6y8A1XFtjajhU60V1QNYnCOxk3t1m0dV0JvA==\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Here, BAACs8MW1xyMe7\u002F8ONd2QwtG3mw37wF1\u002F1pQ6D09xXqf56ncfRtCun6y8A1XFtjajhU60V1QNYnCOxk3t1m0dV0JvA== is the encrypted password.\u003C\u002Fp>\u003Cp>The following files are required as decryption keys:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fconfigkeystore.pass\u003C\u002Fli>\u003Cli>\u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fconfigkeystore.bcfks\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Encrypted information in the database\u003C\u002Fh3>\u003Cp>The password of the admin user is encrypted and stored in the database\u003C\u002Fp>\u003Cp>Query command: saas=&gt; SELECT \"passwordAuthData\" FROM \"PasswordInformation\";\u003C\u002Fp>\u003Cp>Query result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017480872_6_a7cc4e2a16.jpeg\">\u003C\u002Fp>\u003Cp>Main implementation code for encryption 1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>   private String AES_encrypt(@Nonnull byte[] clearData, @Nonnull byte[] key, @Nonnull EncryptionAlgorithms encAlg) throws EncryptionServiceException {\u003Cbr>        Preconditions.checkNotNull(clearData);\u003Cbr>        Preconditions.checkNotNull(key);\u003Cbr>        Preconditions.checkNotNull(encAlg);\u003Cbr>        Preconditions.checkArgument(clearData.length != 0);\u003Cbr>\u003Cbr>        try {\u003Cbr>            String cipherName = encAlg.getCipherName();\u003Cbr>            Cipher cipher = Cipher.getInstance(cipherName, provider);\u003Cbr>            int nonceSize = encAlg.getNonceSize(cipher.getBlockSize());\u003Cbr>            IvParameterSpec ivSpec = null;\u003Cbr>            String encodedIv;\u003Cbr>            if (nonceSize &gt; 0) {\u003Cbr>                byte[] iv = new byte[nonceSize];\u003Cbr>                srand.nextBytes(iv);\u003Cbr>                ivSpec = new IvParameterSpec(iv);\u003Cbr>                encodedIv = new String(Hex.encode(iv), StandardCharsets.US_ASCII);\u003Cbr>            } else {\u003Cbr>                encodedIv = \"\";\u003Cbr>            }\u003Cbr>\u003Cbr>            if (encAlg.forcePadding()) {\u003Cbr>                clearData = ArrayUtils.add(clearData, (byte)1);\u003Cbr>            }\u003Cbr>\u003Cbr>            SecretKey secret = new SecretKeySpec(key, cipherName);\u003Cbr>            cipher.init(1, secret, ivSpec, srand);\u003Cbr>            byte[] data = cipher.doFinal(clearData);\u003Cbr>            String output = Integer.toString(4) + \":\" + encodedIv + \":\" + new String(Hex.encode(data), StandardCharsets.US_ASCII);\u003Cbr>            return output;\u003Cbr>        } catch (InvalidKeyException | BadPaddingException | IllegalBlockSizeException | InvalidAlgorithmParameterException | NoSuchPaddingException | NoSuchAlgorithmException | FipsUnapprovedOperationError var12) {\u003Cbr>            log.error(\"Failed to encrypt with AES: \" + var12.getMessage());\u003Cbr>            throw new EncryptionServiceException(var12);\u003Cbr>        }\u003Cbr>    }\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Main implementation code for encryption 2:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>String encryptedData = Integer.toString(1) + \",\" + encKey.getSafeUuid().toString() + \",\" + this.AES_encrypt(clearData, aesKey, encAlg);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Port 5.8443 login password\u003C\u002Fh3>\u003Cp>Login password is encrypted and saved in the file \u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fconfig-admin.json\u003C\u002Fp>\u003Cp>Main implementation code for encryption:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>    private void setPassword(String newPassword, boolean isSet) throws AdminAuthException {\u003Cbr>        int ic = this.passwordAuthenticationUtil.getIc(iterationCountBase, iterationCountRange);\u003Cbr>\u003Cbr>        try {\u003Cbr>            String newEncryptedPassword = this.passwordAuthenticationUtil.createPWInfo(\"admin\", \"admin\", ic, newPassword);\u003Cbr>            PasswordInfo newPasswordInfo = new PasswordInfo(newEncryptedPassword, isSet);\u003Cbr>            if (this.passwordInfo != null) {\u003Cbr>                newPasswordInfo.setAttemptDelay(this.passwordInfo.getAttemptDelay());\u003Cbr>                newPasswordInfo.setMaxAttemptCount(this.passwordInfo.getMaxAttemptCount());\u003Cbr>            }\u003Cbr>\u003Cbr>            objectMapper.writeValue(this.passwordInfoFile, newPasswordInfo);\u003Cbr>        } catch (IOException | EncryptionServiceException var7) {\u003Cbr>            throw new AdminAuthException(\"Failed to set password\" + var7.getMessage(), var7);\u003Cbr>        }\u003Cbr>\u003Cbr>        try {\u003Cbr>            this.loadEncryptedPasswordFromFile();\u003Cbr>        } catch (IOException var6) {\u003Cbr>            throw new AdminAuthException(\"Failed to load stored password\" + var6.getMessage(), var6);\u003Cbr>        }\u003Cbr>    }\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After setting up the VMware Workspace ONE Access vulnerability debugging environment, we can proceed to study the vulnerability and the method for decrypting database credentials.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article details the process of setting up a VMware Workspace ONE Access vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>VMware Workspace ONE Access Installation\u003C\u002Fli>\u003Cli>VMware Workspace ONE Access Vulnerability Debugging Environment Configuration\u003C\u002Fli>\u003Cli>Common Knowledge\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 VMware Workspace ONE Access Installation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference Materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.vmware.com\u002Fen\u002FVMware-Workspace-ONE-Access\u002F20.01\u002Fworkspace_one_access_install.pdf\u003C\u002Fp>\u003Ch3>1. Download the OVA File\u003C\u002Fh3>\u003Cp>Download page:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fcustomerconnect.vmware.com\u002Fdownloads\u002Fsearch?query=workspace%20one%20access\u003C\u002Fp>\u003Cp>Registration is required before downloading, then select the desired version to download\u003C\u002Fp>\u003Cp>Download page for VMware Workspace ONE Access 21.08.0.1: https:\u002F\u002Fcustomerconnect.vmware.com\u002Fdownloads\u002Fdetails?downloadGroup=WS1A_ONPREM_210801&amp;productId=1269\u003C\u002Fp>\u003Cp>Download file identity-manager-21.08.0.1-19010796_OVF10.ova\u003C\u002Fp>\u003Ch3>2. Installation\u003C\u002Fh3>\u003Ch4>(1) Import the OVA file in VMware Workstation\u003C\u002Fh4>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>VMware Workstation version must be greater than 14, otherwise an error will occur indicating inability to import\u003C\u002Fp>\u003Cp>Set the Host Name on the installation page. If DHCP is configured, other options do not need to be set. My configuration uses a static IP, configured as shown in the image below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017291780_0_a1ffbd9eed-1.jpeg\">\u003C\u002Fp>\u003Cp>After the OVA file import is complete, it will automatically power on for initialization. After initialization is complete, it will appear as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017322087_1_a354d3d868-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Configuration\u003C\u002Fh4>\u003Cp>Modify the local hosts file to point 192.168.1.11 to workspaceone.test.com\u003C\u002Fp>\u003Cp>Access the configuration page at https:\u002F\u002Fworkspaceone.test.com:8443\u003C\u002Fp>\u003Cp>Set passwords for admin, root, and sshuser users; passwords must include uppercase letters, lowercase letters, numbers, and special characters\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>My test results show that the password length must be set to 14, otherwise root and sshuser users cannot log in\u003C\u002Fp>\u003Cp>In my test environment, the password is set to Password@12345, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017371211_2_850096d6b1-1.jpeg\">\u003C\u002Fp>\u003Cp>Set up the database; for ease of environment setup, select Internal Database here\u003C\u002Fp>\u003Cp>Wait for the installation to complete, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017395296_3_6919fa737b-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Enable remote SSH login for the root user\u003C\u002Fh3>\u003Cp>To log in to VMware Workspace ONE Access and modify the system configuration file, there are two login methods:\u003C\u002Fp>\u003Ch4>(1) Log in directly as the root user in the virtual machine\u003C\u002Fh4>\u003Cp>Select Login, enter root and the password Password@12345\u003C\u002Fp>\u003Ch4>(2) Log in via SSH as the sshuser user\u003C\u002Fh4>\u003Cp>After logging in, switch to the root user\u003C\u002Fp>\u003Cp>After switching to the root user, execute the following commands in sequence:\u003C\u002Fp>\u003Cul>\u003Cli>vi \u002Fetc\u002Fssh\u002Fsshd_config\u003C\u002Fli>\u003Cli>Change PermitRootLogin from no to yes\u003C\u002Fli>\u003Cli>systemctl restart sshd\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Enable remote debugging function\u003C\u002Fh3>\u003Cp>Modify the file: \u002Fopt\u002Fvmware\u002Fhorizon\u002Fworkspace\u002Fbin\u002Fsetenv.sh\u003C\u002Fp>\u003Cp>Modify the JVM_OPTS parameter, add: -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8000\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017440225_4_c68d49328e-1.jpeg\">\u003C\u002Fp>\u003Cp>Restart the system\u003C\u002Fp>\u003Cp>Open the firewall: iptables -P INPUT ACCEPT &amp;&amp; iptables -P OUTPUT ACCEPT\u003C\u002Fp>\u003Cp>Set remote debugging parameters in IDEA, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017466562_5_14c23726f6-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For the complete configuration method of IDEA, please refer to the previous article 'Setting Up Zimbra Vulnerability Debugging Environment'\u003C\u002Fp>\u003Ch2>0x03 Common Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Common Commands\u003C\u002Fh3>\u003Cp>Check system service status: chkconfig --list\u003C\u002Fp>\u003Cp>Check all service status: systemctl status\u003C\u002Fp>\u003Cp>Check IP address: ip addr show\u003C\u002Fp>\u003Cp>Check Host Name: hostname\u003C\u002Fp>\u003Cp>Log path: \u002Fopt\u002Fvmware\u002Fhorizon\u002Fworkspace\u002Flogs\u002F\u003C\u002Fp>\u003Ch3>2. Check System Version\u003C\u002Fh3>\u003Cp>Requires root privileges to execute command: vamicli version --appliance\u003C\u002Fp>\u003Cp>Implementation details for checking system version:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#!\u002Fusr\u002Fbin\u002Fenv python2\u003Cbr>import sys\u003Cbr>sys.path.append(\"\u002Fopt\u002Fvmware\u002Flib\u002Fpython\u002Fsite-packages\u002F\")\u003Cbr>import pywbem\u003Cbr>def getCIMConnection (url, namespace):\u003Cbr>    cred = {}\u003Cbr>    cred ['cert_file'] = '\u002Fopt\u002Fvmware\u002Fetc\u002Fsfcb\u002Fclient.pem'\u003Cbr>    cred ['key_file'] = '\u002Fopt\u002Fvmware\u002Fetc\u002Fsfcb\u002Ffile.pem'\u003Cbr>    cliconn = pywbem.WBEMConnection (url, None, namespace, cred)\u003Cbr>    return cliconn\u003Cbr>\u003Cbr>def showVersion():\u003Cbr>  try:\u003Cbr>    cliconn = getCIMConnection ('https:\u002F\u002Flocalhost:5489', 'root\u002Fcimv2')\u003Cbr>    esis = cliconn.EnumerateInstances ('VAMI_ElementSoftwareIdentity')\u003Cbr>  except:\u003Cbr>    print('error')\u003Cbr>    return\u003Cbr>  for esi in esis:\u003Cbr>    ess = esi ['ElementSoftwareStatus']\u003Cbr>    if (ess == [2, 6]):\u003Cbr>      inst = cliconn.GetInstance (esi['Antecedent'])\u003Cbr>      print ('Version - ' + inst ['VersionString'])\u003Cbr>      print ('Description - ' + inst ['Description'])\u003Cbr>showVersion()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Root privileges are required because accessing the files \u002Fopt\u002Fvmware\u002Fetc\u002Fsfcb\u002Fclient.pem and \u002Fopt\u002Fvmware\u002Fetc\u002Fsfcb\u002Ffile.pem requires root permissions.\u003C\u002Fp>\u003Ch3>3. Database Connection Password\u003C\u002Fh3>\u003Cp>The plaintext password for connecting to the database is located at: \u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fdb.pwd\u003C\u002Fp>\u003Cp>The encrypted password for connecting to the database is stored in the file \u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fruntime-config.properties. Example file content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>datastore.jdbc.url=jdbc:postgresql:\u002F\u002Flocalhost\u002Fsaas?stringtype=unspecified\u003Cbr>datastore.jdbc.userName=horizon\u003Cbr>secure.datastore.jdbc.password=BAACs8MW1xyMe7\u002F8ONd2QwtG3mw37wF1\u002F1pQ6D09xXqf56ncfRtCun6y8A1XFtjajhU60V1QNYnCOxk3t1m0dV0JvA==\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Here, BAACs8MW1xyMe7\u002F8ONd2QwtG3mw37wF1\u002F1pQ6D09xXqf56ncfRtCun6y8A1XFtjajhU60V1QNYnCOxk3t1m0dV0JvA== is the encrypted password.\u003C\u002Fp>\u003Cp>The following files are required as decryption keys:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fconfigkeystore.pass\u003C\u002Fli>\u003Cli>\u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fconfigkeystore.bcfks\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Encrypted information in the database\u003C\u002Fh3>\u003Cp>The password of the admin user is encrypted and stored in the database\u003C\u002Fp>\u003Cp>Query command: saas=&gt; SELECT \"passwordAuthData\" FROM \"PasswordInformation\";\u003C\u002Fp>\u003Cp>Query result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017480872_6_a7cc4e2a16-1.jpeg\">\u003C\u002Fp>\u003Cp>Main implementation code for encryption 1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>   private String AES_encrypt(@Nonnull byte[] clearData, @Nonnull byte[] key, @Nonnull EncryptionAlgorithms encAlg) throws EncryptionServiceException {\u003Cbr>        Preconditions.checkNotNull(clearData);\u003Cbr>        Preconditions.checkNotNull(key);\u003Cbr>        Preconditions.checkNotNull(encAlg);\u003Cbr>        Preconditions.checkArgument(clearData.length != 0);\u003Cbr>\u003Cbr>        try {\u003Cbr>            String cipherName = encAlg.getCipherName();\u003Cbr>            Cipher cipher = Cipher.getInstance(cipherName, provider);\u003Cbr>            int nonceSize = encAlg.getNonceSize(cipher.getBlockSize());\u003Cbr>            IvParameterSpec ivSpec = null;\u003Cbr>            String encodedIv;\u003Cbr>            if (nonceSize &gt; 0) {\u003Cbr>                byte[] iv = new byte[nonceSize];\u003Cbr>                srand.nextBytes(iv);\u003Cbr>                ivSpec = new IvParameterSpec(iv);\u003Cbr>                encodedIv = new String(Hex.encode(iv), StandardCharsets.US_ASCII);\u003Cbr>            } else {\u003Cbr>                encodedIv = \"\";\u003Cbr>            }\u003Cbr>\u003Cbr>            if (encAlg.forcePadding()) {\u003Cbr>                clearData = ArrayUtils.add(clearData, (byte)1);\u003Cbr>            }\u003Cbr>\u003Cbr>            SecretKey secret = new SecretKeySpec(key, cipherName);\u003Cbr>            cipher.init(1, secret, ivSpec, srand);\u003Cbr>            byte[] data = cipher.doFinal(clearData);\u003Cbr>            String output = Integer.toString(4) + \":\" + encodedIv + \":\" + new String(Hex.encode(data), StandardCharsets.US_ASCII);\u003Cbr>            return output;\u003Cbr>        } catch (InvalidKeyException | BadPaddingException | IllegalBlockSizeException | InvalidAlgorithmParameterException | NoSuchPaddingException | NoSuchAlgorithmException | FipsUnapprovedOperationError var12) {\u003Cbr>            log.error(\"Failed to encrypt with AES: \" + var12.getMessage());\u003Cbr>            throw new EncryptionServiceException(var12);\u003Cbr>        }\u003Cbr>    }\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Main implementation code for encryption 2:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>String encryptedData = Integer.toString(1) + \",\" + encKey.getSafeUuid().toString() + \",\" + this.AES_encrypt(clearData, aesKey, encAlg);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Port 5.8443 login password\u003C\u002Fh3>\u003Cp>Login password is encrypted and saved in the file \u002Fusr\u002Flocal\u002Fhorizon\u002Fconf\u002Fconfig-admin.json\u003C\u002Fp>\u003Cp>Main implementation code for encryption:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>    private void setPassword(String newPassword, boolean isSet) throws AdminAuthException {\u003Cbr>        int ic = this.passwordAuthenticationUtil.getIc(iterationCountBase, iterationCountRange);\u003Cbr>\u003Cbr>        try {\u003Cbr>            String newEncryptedPassword = this.passwordAuthenticationUtil.createPWInfo(\"admin\", \"admin\", ic, newPassword);\u003Cbr>            PasswordInfo newPasswordInfo = new PasswordInfo(newEncryptedPassword, isSet);\u003Cbr>            if (this.passwordInfo != null) {\u003Cbr>                newPasswordInfo.setAttemptDelay(this.passwordInfo.getAttemptDelay());\u003Cbr>                newPasswordInfo.setMaxAttemptCount(this.passwordInfo.getMaxAttemptCount());\u003Cbr>            }\u003Cbr>\u003Cbr>            objectMapper.writeValue(this.passwordInfoFile, newPasswordInfo);\u003Cbr>        } catch (IOException | EncryptionServiceException var7) {\u003Cbr>            throw new AdminAuthException(\"Failed to set password\" + var7.getMessage(), var7);\u003Cbr>        }\u003Cbr>\u003Cbr>        try {\u003Cbr>            this.loadEncryptedPasswordFromFile();\u003Cbr>        } catch (IOException var6) {\u003Cbr>            throw new AdminAuthException(\"Failed to load stored password\" + var6.getMessage(), var6);\u003Cbr>        }\u003Cbr>    }\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After setting up the VMware Workspace ONE Access vulnerability debugging environment, we can proceed to study the vulnerability and the method for decrypting database credentials.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",811,"Onedaysec",5,"published","2026-02-02T07:38:21.453Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"VMware Workspace ONE Access Debugging Environment Setup Guide","VMware Workspace ONE Access, vulnerability debugging, environment setup, OVA installation, SSH configuration, remote debugging",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],678,677,676,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.922Z","2026-07-23T16:01:57.021Z","draft","2026-07-23T16:14:10.151Z"]