Unable to start CAS 6.4.x Tomcat Server after changing the Default KeyStores

Viewed 428

I set up CAS version 6.4.x with Helm and K8s. It works perfectly if I don't change the default keystore which is changeit. However, when I change the key to something else. It can't start the CAS server

WARN [org.apereo.cas.web.CasWebApplicationContext] - <Exception encountered during context initialization - cancelling refresh attempt: org.springframework.context.ApplicationContextException: Failed to start bean 'webServerStartStop'; nested exception is org.springframework.boot.web.server.WebServerException: Unable to start embedded Tomcat server>
java.security.UnrecoverableKeyException: Get Key failed: Given final block not properly padded. Such issues can arise if a bad key is used during decryption. at java.base/sun.security.pkcs12.PKCS12KeyStore.engineGetKey(Unknown Source) at java.base/sun.security.util.KeyStoreDelegator.engineGetKey(Unknown Source) at java.base/java.security.KeyStore.getKey(Unknown Source) at org.apache.tomcat.util.net.SSLUtilBase.getKeyManagers(SSLUtilBase.java:352) at org.apache.tomcat.util.net.SSLUtilBase.createSSLContext(SSLUtilBase.java:245) at org.apache.tomcat.util.net.AbstractJsseEndpoint.createSSLContext(AbstractJsseEndpoint.java:97) ... 33 more 
Caused by: javax.crypto.BadPaddingException: Given final block not properly padded. 
Such issues can arise if a bad key is used during decryption. at java.base/com.sun.crypto.provider.CipherCore.unpad(Unknown Source) at
java.base/com.sun.crypto.provider.CipherCore.fillOutputBuffer(Unknown Source) at java.base/com.sun.crypto.provider.CipherCore.doFinal(Unknown Source) at java.base/com.sun.crypto.provider.PBES2Core.engineDoFinal(Unknown Source) at java.base/javax.crypto.Cipher.doFinal(Unknown Source) at 
java.base/sun.security.pkcs12.PKCS12KeyStore.lambda$engineGetKey$0(Unknown Source) at java.base/sun.security.pkcs12.PKCS12KeyStore$RetryWithZero.run(Unknown Source) ... 39 more

Here the steps I have done so far:

# change the key store password for current cacerts to `password`
keytool -storepasswd -keystore cacerts
# run all the steps to install CAS with K8s
Link: https://apereo.github.io/cas/6.4.x/installation/Kubernetes-Helm-Deployment.html
# After that I also verify to ensure my truststore and thekeystore can be opened with `password` instead of `changeit`
# here is my cas config
cas.http-client.truststore.psw=password
cas.http-client.truststore.file=/etc/cas/truststore
server.ssl.enable=true
server.ssl.key-alias=cas
server.ssl.key-store=file:/etc/cas/thekeystore
server.ssl.key-store-type=PKCS12
server.ssl.key-store-password=password
server.ssl.trust-store=file:/etc/cas/truststore
server.ssl.trust-store-type=PKCS12
server.ssl.trust-store-password=password

It's so weird that I can't start the Tomcat Server with the new password.

Could you please kindly advise what I should do? Cause I can't leave the CAS with default keystore

Best regards, Quang

0 Answers
Related