# Zip with password

**URL:** <https://discourse.nodered.org/t/zip-with-password/85184>\
**Category:** General\
**Created:** [4 February 2024 12:47 UTC](https://discourse.nodered.org/t/zip-with-password/85184 "2024-02-04T12:47:16Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![robvoi](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/robvoi/32/85198_2.png) [@robvoi](https://discourse.nodered.org/u/robvoi)\
**Post date:** [4 February 2024 12:47 UTC](https://discourse.nodered.org/t/zip-with-password/85184/1 "2024-02-04T12:47:16Z")

</div>

Hi,  
I'm looking for a way to generate a password protected .zip file.  
I want to use it to send mails with encrypted zip as attachment.

Does someone know if/how this can be done?

Thanks

---

<div class="post-metadata">

**Author:** ![ghayne](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ghayne/32/39_2.png) [@ghayne](https://discourse.nodered.org/u/ghayne)\
**Post date:** [4 February 2024 15:36 UTC](https://discourse.nodered.org/t/zip-with-password/85184/2 "2024-02-04T15:36:29Z")

</div>

Which OS? Windows / Linux / Mac.

---

<div class="post-metadata">

**Author:** ![robvoi](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/robvoi/32/85198_2.png) [@robvoi](https://discourse.nodered.org/u/robvoi)\
**Post date:** [4 February 2024 16:21 UTC](https://discourse.nodered.org/t/zip-with-password/85184/3 "2024-02-04T16:21:51Z")

</div>

Linux.  
Node-Red running as Docker.

---

<div class="post-metadata">

**Author:** ![ghayne](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ghayne/32/39_2.png) [@ghayne](https://discourse.nodered.org/u/ghayne)\
**Post date:** [4 February 2024 16:24 UTC](https://discourse.nodered.org/t/zip-with-password/85184/4 "2024-02-04T16:24:07Z")

</div>

You could do this with an exec node:

> **[How to ZIP file with password on Linux](https://linuxconfig.org/how-to-zip-file-with-password-on-linux)**
>
> In this tutorial, we show the command line and GUI instructions to zip files with a password on a Linux system.

---

<div class="post-metadata">

**Author:** ![robvoi](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/robvoi/32/85198_2.png) [@robvoi](https://discourse.nodered.org/u/robvoi)\
**Post date:** [4 February 2024 16:38 UTC](https://discourse.nodered.org/t/zip-with-password/85184/5 "2024-02-04T16:38:44Z")

</div>

I'll try that. Thanks.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [4 February 2024 16:43 UTC](https://discourse.nodered.org/t/zip-with-password/85184/6 "2024-02-04T16:43:04Z")

</div>

That could be an issue running in Docker as you will need to have the application installed in the container. Perhaps it is already. @robvoi, Is there a reason you are using Docker?

---

<div class="post-metadata">

**Author:** ![robvoi](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/robvoi/32/85198_2.png) [@robvoi](https://discourse.nodered.org/u/robvoi)\
**Post date:** [4 February 2024 16:46 UTC](https://discourse.nodered.org/t/zip-with-password/85184/7 "2024-02-04T16:46:54Z")

</div>

Using docker, because it is running as part of a bigger selfhosted environment.

It worked.  
I had to install zip in the container. So I need to install it again, when I update the container. But that's ok.

Thanks

---

<div class="post-metadata">

**Author:** ![ghayne](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ghayne/32/39_2.png) [@ghayne](https://discourse.nodered.org/u/ghayne)\
**Post date:** [4 February 2024 16:49 UTC](https://discourse.nodered.org/t/zip-with-password/85184/8 "2024-02-04T16:49:39Z")

</div>

Good. Also be aware that ZIP encryption is not very secure!

---

<div class="post-metadata">

**Author:** ![robvoi](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/robvoi/32/85198_2.png) [@robvoi](https://discourse.nodered.org/u/robvoi)\
**Post date:** [4 February 2024 16:58 UTC](https://discourse.nodered.org/t/zip-with-password/85184/9 "2024-02-04T16:58:18Z")

</div>

OK. Thanks for the warning!

---

<div class="post-metadata">

**Author:** ![meeki007](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/meeki007/32/12499_2.png) [@meeki007](https://discourse.nodered.org/u/meeki007)\
**Post date:** [4 February 2024 19:30 UTC](https://discourse.nodered.org/t/zip-with-password/85184/10 "2024-02-04T19:30:29Z")

</div>

> [@ghayne](#):
>
> Good. Also be aware that ZIP encryption is not very secure!

@ghayne Is trying to help you here.

please Encrypt / protect the data before you zip. If you want it secure.

Cpu core counts are getting cheap. My used 2017 server I picked up for $700 eats zip passwords for breakfast.

 ![Screenshot from 2024-02-04 14-22-41](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/f/f/ff8337ad9513da137bf1c0498d20491769a33f44.jpeg)

---

<div class="post-metadata">

**Author:** ![AndrewBeasley](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@AndrewBeasley](https://discourse.nodered.org/u/AndrewBeasley)\
**Post date:** [5 February 2024 01:25 UTC](https://discourse.nodered.org/t/zip-with-password/85184/11 "2024-02-05T01:25:53Z")

</div>

Rather than manually install zip each time you update the container use Docker Compose as this gives you the ability to add packages (or run specific commands) in each time automatically...

Plenty of examples around but this may get you started [https://www.baeldung.com/ops/docker-compose-multiple-commands](https://www.baeldung.com/ops/docker-compose-multiple-commands)

---

<div class="post-metadata">

**Author:** ![robvoi](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/robvoi/32/85198_2.png) [@robvoi](https://discourse.nodered.org/u/robvoi)\
**Post date:** [5 February 2024 06:27 UTC](https://discourse.nodered.org/t/zip-with-password/85184/12 "2024-02-05T06:27:51Z")

</div>

Pure brute force?  
Just out of curiosity, how long does it chew on a random 32 char (stong) password?

---

<div class="post-metadata">

**Author:** ![robvoi](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/robvoi/32/85198_2.png) [@robvoi](https://discourse.nodered.org/u/robvoi)\
**Post date:** [5 February 2024 06:28 UTC](https://discourse.nodered.org/t/zip-with-password/85184/13 "2024-02-05T06:28:26Z")

</div>

Perfect. I’ll dig into this.

---

<div class="post-metadata">

**Author:** ![meeki007](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/meeki007/32/12499_2.png) [@meeki007](https://discourse.nodered.org/u/meeki007)\
**Post date:** [5 February 2024 11:39 UTC](https://discourse.nodered.org/t/zip-with-password/85184/14 "2024-02-05T11:39:55Z")

</div>

> [@robvoi](#):
>
> Just out of curiosity, how long does it chew on a random 32 char (stong) password?

Using tables  
32 char - 10 of millions of years  
16 char - years/months  
12 char - days/hours  
8 char - minutes

Truly random using full 94 char set  
32 char - 100 of millions of years  
16 char - 10 of millions of years  
12 char - years/months  
8 char - days/hours

If i know its 32 char long using the standard 94 char set - 1 million years give or take 🙂

[https://manpages.ubuntu.com/manpages/xenial/man1/fcrackzip.1.html](https://manpages.ubuntu.com/manpages/xenial/man1/fcrackzip.1.html)

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [5 February 2024 12:35 UTC](https://discourse.nodered.org/t/zip-with-password/85184/15 "2024-02-05T12:35:57Z")

</div>

> [@meeki007](#):
>
> Cpu core counts are getting cheap. My used 2017 server I picked up for $700 eats zip passwords for breakfast.

> [@meeki007](#):
>
> If i know its 32 char long using the standard 94 char set - 1 million years give or take

That is one loooooooong breakfast 😉

---

<div class="post-metadata">

**Author:** ![robvoi](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/robvoi/32/85198_2.png) [@robvoi](https://discourse.nodered.org/u/robvoi)\
**Post date:** [5 February 2024 19:53 UTC](https://discourse.nodered.org/t/zip-with-password/85184/16 "2024-02-05T19:53:56Z")

</div>

OK. that's confidential enough for my use case. 😛  
Integrity doesn't matter in it.

Thanks for all the support and information. 🙂

---

<div class="post-metadata">

**Author:** ![AndrewBeasley](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@AndrewBeasley](https://discourse.nodered.org/u/AndrewBeasley)\
**Post date:** [5 February 2024 21:49 UTC](https://discourse.nodered.org/t/zip-with-password/85184/17 "2024-02-05T21:49:10Z")

</div>

> [@Steve-Mcl](#):
>
> ...
> 
> > [@meeki007](#):
> >
> > If i know its 32 char long using the standard 94 char set - 1 million years give or take
> 
> That is one loooooooong breakfast 😉

Not if you are a hobbit 😄

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [5 May 2024 21:49 UTC](https://discourse.nodered.org/t/zip-with-password/85184/18 "2024-05-05T21:49:17Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
