{"record":{"id":"4a4fbe06b6ce5a15","repo":"vectordotdev/vector","slug":"invalid-stored-identity","errorCode":null,"errorMessage":"Invalid stored identity","messagePattern":"Invalid stored identity","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"lib/vector-core/src/tls/settings.rs","lineNumber":244,"sourceCode":"    /// The configured SNI server name override, if any.\n    pub fn server_name(&self) -> Option<&str> {\n        self.server_name.as_deref()\n    }\n\n    /// Whether certificate hostname verification is enabled.\n    pub fn verify_hostname(&self) -> bool {\n        self.verify_hostname\n    }\n\n    /// Returns the identity as PEM encoded byte arrays\n    ///\n    /// # Panics\n    ///\n    /// Panics if the identity is missing, invalid, or the authorities to chain are invalid.\n    pub fn identity_pem(&self) -> Option<(Vec<u8>, Vec<u8>)> {\n        self.identity.as_ref().map(|identity| {\n            // we have verified correct formatting at ingest time\n            let mut cert = identity.cert.to_pem().expect(\"Invalid stored identity\");\n            let key = identity\n                .key\n                .private_key_to_pem_pkcs8()\n                .expect(\"Invalid stored identity\");\n            if let Some(chain) = identity.ca.as_ref() {\n                for authority in chain {\n                    cert.extend(\n                        authority\n                            .to_pem()\n                            .expect(\"Invalid stored identity chain certificate\"),\n                    );\n                }\n            }\n            (cert, key)\n        })\n    }\n\n    /// Returns the authorities as PEM data","sourceCodeStart":226,"sourceCodeEnd":262,"githubUrl":"https://github.com/vectordotdev/vector/blob/bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013/lib/vector-core/src/tls/settings.rs#L226-L262","documentation":"`identity_pem` serializes a stored TLS identity (OpenSSL `X509` cert and `PKey`) back to PEM bytes and panics with \"Invalid stored identity\" if `to_pem()` or `private_key_to_pem_pkcs8()` fails. The code assumes identity was validated at ingest time, so a failure here means the stored identity object is unusable — an internal invariant break.","triggerScenarios":"Calling `TlsSettings::identity_pem()` when `identity.cert.to_pem()` or `identity.key.private_key_to_pem_pkcs8()` fails — e.g. the key/cert objects were constructed from malformed or mismatched data that bypassed ingest-time validation, or the key is an unsupported type for PKCS#8 serialization.","commonSituations":"TLS config files whose cert and key do not match or are in exotic formats that parsed but cannot re-serialize; identities loaded programmatically in tests without the usual validation path; OpenSSL backend limitations with certain key algorithms (e.g. unusual EC curves) failing PKCS#8 export.","solutions":["Regenerate or re-export the certificate/key pair into standard PEM (X.509 cert + PKCS#8 key) and reconfigure TLS settings.","Verify the configured `key` and `crt` files are a matching pair and parse cleanly with `openssl x509` / `openssl pkey`.","Validate the identity at load time with the library's normal `TlsSettings::from_options` path instead of constructing `Identity` objects manually.","If a specific key algorithm fails PKCS#8 export, convert the key (e.g. `openssl pkcs8 -topk8`) before use."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Validate the pair loads and re-serializes before configuring TLS\nlet cert = openssl::x509::X509::from_pem(&cert_pem)?;\nlet key = openssl::pkey::PKey::private_key_from_pem(&key_pem)?;\ncert.to_pem().expect(\"cert serializes\");\nkey.private_key_to_pem_pkcs8().expect(\"key serializes to PKCS#8\");\n// also check public keys match:\nassert_eq!(cert.public_key()?.public_eq(&key), true, \"cert/key mismatch\");","typeGuard":"fn identity_is_serializable(cert: &openssl::x509::X509, key: &openssl::pkey::PKey<Private>) -> bool {\n    cert.to_pem().is_ok() && key.private_key_to_pem_pkcs8().is_ok()\n}","tryCatchPattern":"// The library panics; pre-validate in your own loader so identity_pem is never reached with a bad pair\nfn load_identity(pem: &[u8], key: &[u8]) -> anyhow::Result<Identity> {\n    let cert = X509::from_pem(pem)?;\n    let key = PKey::private_key_from_pem(key)?;\n    cert.to_pem().context(\"cert to_pem failed\")?;\n    key.private_key_to_pem_pkcs8().context(\"key to pkcs8 failed\")?;\n    Ok(Identity { cert, key, ca: None })\n}","preventionTips":["Always load TLS identity through TlsSettings::from_options so ingest-time validation runs.","Verify cert and key match (public_eq check) before storing the identity.","Convert keys to PKCS#8 up front (openssl pkcs8 -topk8) so private_key_to_pem_pkcs8 cannot fail.","Test TLS config files at startup with openssl x509/openssl pkey rather than discovering failures mid-connection."],"tags":["rust","tls","openssl","certificate"],"backgroundTag":"invalid-pem-certificate","analyzedSha":"bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013","analyzedAt":"2026-09-16T02:53:35.741Z","contentChangedAt":"2026-09-16T02:53:35.741Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}