IBMDO YOU?Hi, I'm MBO!

Settings

Make the site feel at home on your screen.

Theme

Loading your theme preference.

Keyboard shortcuts

Open search from anywhere, then move through the results without leaving the keyboard.

Open settings
Ctrl,or⌘,
Open search
CtrlKor⌘K
Select a search result
↑↓
Open the selected result
Enter
Close an open dialog
Esc

I Bend Maximo

Decrypt Maximo passwords with the IBM DO YOU? tool

Use the IBM DO YOU? password decrypter to inspect Maximo native-authentication values individually or in bulk.

Traditional Maximo installations that use native authentication store an encrypted password in MAXUSER.PASSWORD. I have added a tool to IBM DO YOU? that can decrypt those values individually or in a controlled batch.

You can open it here:

Open the Maximo password decrypter

The article is public, but the decrypter itself requires the tools password.

When the tool is useful

The decrypter is intended for controlled administration and troubleshooting of Maximo environments you are authorized to manage. It can help when you need to:

  • Investigate a legacy native-authentication configuration.
  • Confirm which credential an integration or test account is using.
  • Review accounts while recovering or refreshing a non-production environment.
  • Compare a small controlled set of stored credentials during an investigation.

It does not apply to passwords managed by LDAP, Active Directory, an identity provider or application-server authentication. Those systems do not use the native Maximo value in the same way.

Decryption also does not tell you whether a password is current in an external system, safe to keep using or known by the person who owns the account. Treat the result as a credential from the moment it appears.

Retrieve the encrypted value

Use a read-only database account and select only the accounts needed for the investigation. The PASSWORD column contains binary data, so the query must convert it to hexadecimal text before you paste it into the tool.

DB2

Use DB2's HEX function:

SELECT
  USERID,
  LOGINID,
  HEX(PASSWORD) AS PASSWORD_HEX
FROM
  MAXUSER
WHERE
  USERID = 'MAXADMIN';

Oracle

Use Oracle's RAWTOHEX function:

SELECT
  USERID,
  LOGINID,
  RAWTOHEX(PASSWORD) AS PASSWORD_HEX
FROM
  MAXUSER
WHERE
  USERID = 'MAXADMIN';

SQL Server

Use conversion style 2 to return hexadecimal text without a leading 0x:

SELECT
  USERID,
  LOGINID,
  CONVERT(VARCHAR(MAX), PASSWORD, 2) AS PASSWORD_HEX
FROM
  MAXUSER
WHERE
  USERID = 'MAXADMIN';

Each query returns the same kind of hexadecimal value expected by Encrypted password (hex). Change the predicate to LOGINID = 'maxadmin' when the login ID is the identifier you know.

Do not export the complete user table by default. Restrict the query to the accounts required for the task and protect the query results as you would protect plaintext passwords.

Decrypt one password

Open the Maximo password decrypter and enter the tools password. The access cookie is HTTP-only, restricted to the tool and expires after eight hours.

For a single value:

  1. Enter the Maximo login ID. This is optional, but it makes multiple results easier to identify.
  2. Paste the hexadecimal value from MAXUSER.PASSWORD into Encrypted password (hex).
  3. Select Decrypt passwords.
  4. Use the copy icon inside the decrypted-password field if you need to move the result directly into another approved tool.
  5. Select Check strength to review the password's estimated strength, improvement suggestions and guessing times.

The input can include an optional 0x prefix. Surrounding whitespace is ignored; other spaces and non-hexadecimal characters are rejected rather than silently altered.

Check the password strength

The strength checker runs in the browser after a password has been decrypted. Opening it does not send the plaintext through another API request.

The analysis looks for common passwords, names, dictionary words, dates, repeated characters, keyboard patterns and predictable substitutions. It returns a score from one to five, practical suggestions and estimated guessing times for several attack rates.

Those times estimate the difficulty of guessing the password. They do not measure how safely MAXUSER.PASSWORD protects it: Maximo stores this value with reversible encryption, so anyone who obtains both the database value and encryption key can decrypt it without guessing. Use the score to identify weak credentials and prioritize a password change, rather than as proof that the stored value is secure.

Process several values

Select Add row to enter more accounts manually. The tool processes every row containing an encrypted value and reports an error against an individual row when that value cannot be decrypted.

For a larger controlled set, select Import CSV. The file can contain either an encrypted value by itself:

32EADE0476E145253F31C2002DFA7F3E4B9902366B8E08F1

or a login ID followed by the encrypted value:

maxadmin,32EADE0476E145253F31C2002DFA7F3E4B9902366B8E08F1

The tool accepts up to 100 rows in one request. Download results creates a CSV containing the login ID, encrypted value, decrypted value and any row error. That downloaded file contains plaintext credentials, so store it only when necessary, restrict access to it and delete it securely when the task is complete.

Encryption settings

The standard Maximo native-authentication settings are already loaded. They use:

  • The DESede algorithm, commonly called Triple DES or 3DES.
  • CBC mode.
  • PKCS#5 padding.
  • The standard Maximo encryption key and initialization specification.

Open Advanced encryption settings only when the source environment was deliberately configured with different values. All five settings must match the environment that encrypted the password. A wrong key or initialization specification normally produces a decryption error or meaningless output.

Restore defaults returns every advanced field to the standard Maximo values.

What happens to the values

The browser sends the submitted encrypted values to the IBM DO YOU? server over the current HTTPS connection. A server-only route performs the decryption in memory and returns the result to the page.

The decryption response is marked no-store, and the application does not write submitted values or decrypted passwords to its content files or application logs. The plaintext still exists in the browser after decryption and may be copied or downloaded at your request, so browser access, screen sharing, clipboard history and downloaded files all need the same care as any other credential-handling workflow.

Use Clear when you finish. Closing the page removes the displayed values, although it cannot remove copies you placed on the clipboard or saved to disk.

If decryption fails

Check the following before changing the advanced settings:

  • Copy only the encrypted password value, without column labels or CSV quotation marks.
  • Confirm that the value contains an even number of hexadecimal characters.
  • Confirm that the account came from a Maximo native-authentication environment.
  • Check that the database result was not truncated by the SQL client or export format.
  • Confirm that the source environment did not override Maximo's standard encryption settings.

An account may also contain a value produced by a different Maximo configuration or authentication path. Do not treat a failed decryption as proof that the database value is damaged.

Prefer changing a password when possible

Decryption is useful for investigation, but it should not become the normal way to distribute credentials. When the goal is simply to restore access, reset the account to a new approved password, update its dependent integrations securely and record the change through the normal operational process.

The separate reset MAXADMIN's password procedure covers recovery for traditional Maximo native authentication when the existing password is unavailable.

Find the fix

Search articles

Esc

Search titles, technical terms or error codes.