When trying to return cleartext passwords from the pwextractor utility in PIM an error like the one below is received. Even though the utility continues on and claims to successfully complete. When reviewing the output file it only contains the CSV style header information and no information about accounts.
Starting passwords extraction for ACCOUNT_PASSWORD...... 2018-08-02 16:14:58,021 (com.netegrity.crypto.AESCBCPKCS5PaddingHandler) ERROR - Exception caught while encrypting. 2018-08-02 16:14:58,023 (com.netegrity.crypto.AESCBCPKCS5PaddingHandler) ERROR - ; com.rsa.jsafe.JSAFE_PaddingException: Could not perform unpadding: invalid p ad byte. Successfully completed password extraction to file is: c:\production_accounts_pa sswd Signed file successfully to c:\production_accounts_passwd.sig Press any key to continue . . .
%[email protected]!~CLEAR_TEXT% %[email protected][email protected]!~PASSWORD_LAST_MODIFIED_DATE
The problem here is related to the password decryption.This error is usually caused by using the incorrect KIPSkey.dat file when running the pwextractor command. It may also be caused by attempting to use a corrupted FIPSkey.dat file.
Any PIM version
To resolve this issue you need to make sure you are using the correct FIPSkey.dat.