This documentation is for WSO2 Carbon 4.4.3. View documentation for the latest release.
Page Comparison - Encrypting Passwords with Cipher Tool (v.11 vs v.12) - Carbon 4.4.3 - WSO2 Documentation
Due to a known issue do not use JDK1.8.0_151 with WSO2 products. Use JDK 1.8.0_144 until JDK 1.8.0_162-ea is released.

Versions Compared


  • This line was added.
  • This line was removed.
  • Formatting was changed.


  1. Download and install a WSO2 product.
  2. Open a command prompt and navigate to the <PRODUCT_HOME>/bin folder.
  3. You must first enable the Cipher tool for the product by executing the following command:

    Code Block
    sh -Dconfigure 

    If you are using the cipher tool for the first time, this command will first initialize the tool for your product. The tool will then encrypt any plain text passwords that are specified in the file for automatic encryption.

  4. Now, you can start encrypting the admin password manually. Execute the Cipher tool using the following command:

    Code Block
  5. You will be asked to enter the primary key password, which is by default 'wso2carbon'. Enter the password and proceed.
  6. You will now be asked to enter the plain text password that you want to encrypt. Enter the following element as the password and proceed:

    Code Block
    Enter Plain Text Value :admin

    Note that in certain configuration files, the password that requires encryption may not be specified as a single value as it is in the file. For example, the file used in WSO2 ESB contains the password in the connection URL. In such cases, you need to encrypt the entire connection URL as explained here.

  7. You will receive the encrypted value as shown below. For example:

    Code Block
    Encrypted value is: 
  8. Open the file, stored in the <PRODUCT_HOME>/repository/conf/security folder.

  9. Add the encrypted password against the secret alias as shown below.

    Code Block
  10. Now, open the file, stored in the <PRODUCT_HOME>/repository/conf folder and replace the plain text element with the alias of the encrypted value as shown below.

    Code Block
    # LOGEVENT is set to be a LogEventAppender using a PatternLayout to send logs to LOGEVENT