Uploaded image for project: 'Apache NiFi'
  1. Apache NiFi
  2. NIFI-11133

TLS Toolkit Standalone Mode Sets Null Password for Client Keys

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Minor
    • Resolution: Fixed
    • None
    • 1.20.0
    • None
    • None

    Description

      The TLS Toolkit in Standalone Mode supports the option to generate one or more Client Key Stores. The Standalone Mode generates a Key Pair with a signed Certificate for each client requested and uses a null when adding the Private Key Entry to the Key Store. This approach causes an UnrecoverableKeyException when attempting to read the generated PKCS12 Key Store. The implementation should be corrected to set a Key Password using the value provided for the Key Store Password, which is the standard approach for PKCS12.

      Attachments

        Issue Links

          Activity

            People

              exceptionfactory David Handermann
              exceptionfactory David Handermann
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 20m
                  20m