Encrypt and Decrypt a ZIP Archive with zipcloak
You will finish with a ZIP archive whose unencrypted entries are protected by a password, plus a way to decrypt it into a separate file and verify the result. The examples use the installed Info-ZIP zipcloak 3.0 from Ubuntu package zip 3.0-13ubuntu0.2. Allow about ten minutes, and have a ZIP archive that you can safely copy before changing it.
The route
Jump straight to the step you need, or tick off Done means at the end.
Security boundary
Zipcloak uses the original ZIP encryption scheme, which the local manual describes as weak. Do not use it for new high-value secrets when a modern encrypted archive or encrypted storage option is available. This guide covers compatibility with existing ZIP workflows.
1. Check the installed command
Confirm the binary and its package version. These are ordinary read-only commands and do not need sudo:
$ command -v zipcloak
/usr/bin/zipcloak
$ dpkg-query -W -f='${Package} ${Version}\n' zip
zip 3.0-13ubuntu0.2
$ zipcloak -h
ZipCloak 3.0 (July 5th 2008)
Usage: zipcloak [-dq] [-b path] zipfile
The help output also lists -O, the output-file option. The manual's synopsis is shorter than the installed help text, so prefer the installed help when checking this particular binary. The main actions are encryption by default and decryption with -d.
2. Make a working copy before encryption
Encryption without -O replaces the named archive through a temporary file. That is a change to the archive, so keep an untouched copy first:
$ cp --preserve=all /path/to/archive.zip /path/to/archive-before-zipcloak.zip
$ unzip -t /path/to/archive-before-zipcloak.zip
No errors detected in compressed data of /path/to/archive-before-zipcloak.zip.
Replace both paths with real names. The archive copy is your recovery point. Do not delete it until you have tested the encrypted file and confirmed that you can decrypt it with the intended password.
Checkpoint
Work on the copy, not the only copy. If the source is owned by another account or stored in a protected directory, copy it to a directory you can write as your normal user. Elevated privileges are normally unnecessary.
3. Encrypt the archive in place
Run zipcloak on the working copy:
$ zipcloak /path/to/archive-before-zipcloak.zip
Enter password:
Verify password:
encrypting: report.txt
encrypting: data.csv
Type the password at the prompts. It is not shown on screen. The command encrypts all unencrypted entries in the archive, rather than creating a new archive containing only selected files. Existing encrypted entries are not the target of this default action.
Do not put the password in the command line. Shell history, process inspection and logs can expose command-line arguments. Do not use a password that is also used for an account, SSH key or password manager.
Check that the archive is still structurally sound:
$ unzip -t /path/to/archive-before-zipcloak.zip
Archive: /path/to/archive-before-zipcloak.zip
testing: report.txt OK
testing: data.csv OK
No errors detected in compressed data of /path/to/archive-before-zipcloak.zip.
Depending on the unzip build, the test may ask for the password or report that encrypted entries need a password. That is expected. A successful archive test does not make the encryption strong; it only checks that the archive can be read.
4. Decrypt to a new archive
Use -d with -O when you want to keep the encrypted input unchanged:
$ zipcloak -d -O /path/to/archive-decrypted.zip /path/to/archive-before-zipcloak.zip
Enter password:
decrypting: report.txt
decrypting: data.csv
$ unzip -t /path/to/archive-decrypted.zip
No errors detected in compressed data of /path/to/archive-decrypted.zip.
-O means output file, not overwrite confirmation. The destination must be a different path from the input. If the destination already contains useful data, choose another name or move it aside first. A failed attempt can leave an incomplete destination, so inspect the result before replacing anything else.
To verify that decryption really produced usable unencrypted entries, list the archive and extract one file into a new temporary directory:
$ unzip -l /path/to/archive-decrypted.zip
$ mkdir /tmp/zipcloak-check
$ unzip -q /path/to/archive-decrypted.zip -d /tmp/zipcloak-check
$ test -s /tmp/zipcloak-check/report.txt && echo 'extraction check passed'
extraction check passed
Use a directory that does not contain files you need. Extraction can overwrite files with matching names, so the check directory should be new and disposable.
5. Recover from a wrong password or failed run
Keep the original copy until the round trip works. If you encrypted the wrong archive or need to abandon the change, restore the untouched backup after checking the paths carefully:
$ mv /path/to/archive-before-zipcloak.zip /path/to/archive.zip
This replaces the destination name if it is already present, so stop first if archive.zip contains newer work. A safer recovery is to rename the current file, then rename the backup into place. Do not remove a backup merely because zipcloak returned a zero status.
For decryption, the manual warns that a wrong password may result in entries being copied. Treat the output as untrusted until unzip -t and a real extraction succeed with the password you expect. If they fail, discard the newly created output and retry with the correct password. The encrypted input remains the recovery source when you use -O.
Large files over 2 GB, large archives and split archives are documented limitations of this installed program. For a split archive, first convert it to a single-file archive with zip, then run zipcloak on that archive. Only split the result again after you have verified it. Never test this conversion on the only copy.
Done means
- You checked the installed zipcloak and package versions.
- You retained an untouched archive before changing anything.
- The encrypted archive passed an archive integrity test.
- You used
-d -Oto decrypt into a separate file and tested an extraction. - You did not expose the password in shell history or a process argument.
- You remembered that zipcloak's legacy encryption is weak and unsuitable for high-value new secrets.