Traditional Maximo installations that use native authentication store an encrypted password in MAXUSER.PASSWORD. I have added a tool to IBM DO YOU? that can decrypt those values individually or in a controlled batch.
You can open it here:
Open the Maximo password decrypter
The article is public, but the decrypter itself requires the tools password.
When the tool is useful
The decrypter is intended for controlled administration and troubleshooting of Maximo environments you are authorized to manage. It can help when you need to:
- Investigate a legacy native-authentication configuration.
- Confirm which credential an integration or test account is using.
- Review accounts while recovering or refreshing a non-production environment.
- Compare a small controlled set of stored credentials during an investigation.
It does not apply to passwords managed by LDAP, Active Directory, an identity provider or application-server authentication. Those systems do not use the native Maximo value in the same way.
Decryption also does not tell you whether a password is current in an external system, safe to keep using or known by the person who owns the account. Treat the result as a credential from the moment it appears.
Retrieve the encrypted value
Use a read-only database account and select only the accounts needed for the investigation. The PASSWORD column contains binary data, so the query must convert it to hexadecimal text before you paste it into the tool.
DB2
Use DB2's HEX function:
SELECT
USERID,
LOGINID,
HEX(PASSWORD) AS PASSWORD_HEX
FROM
MAXUSER
WHERE
USERID = 'MAXADMIN';Oracle
Use Oracle's RAWTOHEX function:
SELECT
USERID,
LOGINID,
RAWTOHEX(PASSWORD) AS PASSWORD_HEX
FROM
MAXUSER
WHERE
USERID = 'MAXADMIN';SQL Server
Use conversion style 2 to return hexadecimal text without a leading 0x:
SELECT
USERID,
LOGINID,
CONVERT(VARCHAR(MAX), PASSWORD, 2) AS PASSWORD_HEX
FROM
MAXUSER
WHERE
USERID = 'MAXADMIN';Each query returns the same kind of hexadecimal value expected by Encrypted password (hex). Change the predicate to LOGINID = 'maxadmin' when the login ID is the identifier you know.
Do not export the complete user table by default. Restrict the query to the accounts required for the task and protect the query results as you would protect plaintext passwords.
Decrypt one password
Open the Maximo password decrypter and enter the tools password. The access cookie is HTTP-only, restricted to the tool and expires after eight hours.
For a single value:
- Enter the Maximo login ID. This is optional, but it makes multiple results easier to identify.
- Paste the hexadecimal value from
MAXUSER.PASSWORDinto Encrypted password (hex). - Select Decrypt passwords.
- Use the copy icon inside the decrypted-password field if you need to move the result directly into another approved tool.
- Select Check strength to review the password's estimated strength, improvement suggestions and guessing times.
The input can include an optional 0x prefix. Surrounding whitespace is ignored; other spaces and non-hexadecimal characters are rejected rather than silently altered.
Check the password strength
The strength checker runs in the browser after a password has been decrypted. Opening it does not send the plaintext through another API request.
The analysis looks for common passwords, names, dictionary words, dates, repeated characters, keyboard patterns and predictable substitutions. It returns a score from one to five, practical suggestions and estimated guessing times for several attack rates.
Those times estimate the difficulty of guessing the password. They do not measure how safely MAXUSER.PASSWORD protects it: Maximo stores this value with reversible encryption, so anyone who obtains both the database value and encryption key can decrypt it without guessing. Use the score to identify weak credentials and prioritize a password change, rather than as proof that the stored value is secure.
Process several values
Select Add row to enter more accounts manually. The tool processes every row containing an encrypted value and reports an error against an individual row when that value cannot be decrypted.
For a larger controlled set, select Import CSV. The file can contain either an encrypted value by itself:
32EADE0476E145253F31C2002DFA7F3E4B9902366B8E08F1or a login ID followed by the encrypted value:
maxadmin,32EADE0476E145253F31C2002DFA7F3E4B9902366B8E08F1The tool accepts up to 100 rows in one request. Download results creates a CSV containing the login ID, encrypted value, decrypted value and any row error. That downloaded file contains plaintext credentials, so store it only when necessary, restrict access to it and delete it securely when the task is complete.
Encryption settings
The standard Maximo native-authentication settings are already loaded. They use:
- The
DESedealgorithm, commonly called Triple DES or 3DES. - CBC mode.
- PKCS#5 padding.
- The standard Maximo encryption key and initialization specification.
Open Advanced encryption settings only when the source environment was deliberately configured with different values. All five settings must match the environment that encrypted the password. A wrong key or initialization specification normally produces a decryption error or meaningless output.
Restore defaults returns every advanced field to the standard Maximo values.
What happens to the values
The browser sends the submitted encrypted values to the IBM DO YOU? server over the current HTTPS connection. A server-only route performs the decryption in memory and returns the result to the page.
The decryption response is marked no-store, and the application does not write submitted values or decrypted passwords to its content files or application logs. The plaintext still exists in the browser after decryption and may be copied or downloaded at your request, so browser access, screen sharing, clipboard history and downloaded files all need the same care as any other credential-handling workflow.
Use Clear when you finish. Closing the page removes the displayed values, although it cannot remove copies you placed on the clipboard or saved to disk.
If decryption fails
Check the following before changing the advanced settings:
- Copy only the encrypted password value, without column labels or CSV quotation marks.
- Confirm that the value contains an even number of hexadecimal characters.
- Confirm that the account came from a Maximo native-authentication environment.
- Check that the database result was not truncated by the SQL client or export format.
- Confirm that the source environment did not override Maximo's standard encryption settings.
An account may also contain a value produced by a different Maximo configuration or authentication path. Do not treat a failed decryption as proof that the database value is damaged.
Prefer changing a password when possible
Decryption is useful for investigation, but it should not become the normal way to distribute credentials. When the goal is simply to restore access, reset the account to a new approved password, update its dependent integrations securely and record the change through the normal operational process.
The separate reset MAXADMIN's password procedure covers recovery for traditional Maximo native authentication when the existing password is unavailable.