cloudstack-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Rohit Yadav <>
Subject Re: keystore for manager
Date Thu, 27 Aug 2020 11:00:05 GMT

I've proposed a PR here:

The issue was that newer Jetty 9 on 4.14 and master has deprecated how SSL connections are
handled and fails with keystore related error. I've tested both JKS and PKCS12 type of keystore
with (a) self-signed cert and (b) a valid wildcard cert with cert chains and it worked for


From: Rohit Yadav <>
Sent: Thursday, August 27, 2020 13:21
To: <>; Rafael del Valle <>
Subject: Re: keystore for manager

Hi Rafael, All,

Yes, as you've identified this is a known blocker issue and we're working towards to fixing
that. I think this has to do with migration towards Java11 and change in the default keystore
formats and I'm currently exploring the issue. This has been working with 4.13 that uses Java8.


From: Rafael del Valle <>
Sent: Wednesday, August 26, 2020 23:31
To: <>
Subject: keystore for manager


I am not managing to generate a keystore for the manager (jetty 9 / java 11).

We have done this before many times as we also embed jetty in other projects.

But for some reason it keeps rejecting the keystore.

Anybody has any idea of that this could be about?

This is how we are doing it:

  - name: Generate PKCS#12 file
      action: export
      path: jetty.pkcs12
      friendly_name: jetty
      privatekey_path: Test_Server_Key.pem
      certificate_path: VDC_Test_Server.crt
        - VDC_Test_Intermediate_CA.crt
        - VDC_Test_CA.crt
      state: present
      passphrase: Secret

  - name: Generate Java Key Store
    shell: keytool -importkeystore -srckeystore jetty.pkcs12 -srcstoretype PKCS12 -destkeystore

Any idea what could be going on?

3 London Bridge Street,  3rd floor, News Building, London  SE1 9SGUK
3 London Bridge Street,  3rd floor, News Building, London  SE1 9SGUK

  • Unnamed multipart/alternative (inline, None, 0 bytes)
View raw message