{"record":{"id":"9cf446862fbde168","repo":"spring-projects/spring-boot","slug":"error-decrypting-private-key","errorCode":null,"errorMessage":"Error decrypting private key","messagePattern":"Error decrypting private key","errorType":"validation","errorClass":"IllegalArgumentException","httpStatus":null,"severity":"error","filePath":"buildpack/spring-boot-buildpack-platform/src/main/java/org/springframework/boot/buildpack/platform/docker/ssl/PemPrivateKeyParser.java","lineNumber":464,"sourceCode":"\t */\n\tstatic class Pkcs8PrivateKeyDecryptor {\n\n\t\tpublic static final String PBES2_ALGORITHM = \"PBES2\";\n\n\t\tstatic PKCS8EncodedKeySpec decrypt(byte[] bytes, @Nullable String password) {\n\t\t\tAssert.state(password != null, \"Password is required for an encrypted private key\");\n\t\t\ttry {\n\t\t\t\tEncryptedPrivateKeyInfo keyInfo = new EncryptedPrivateKeyInfo(bytes);\n\t\t\t\tAlgorithmParameters algorithmParameters = keyInfo.getAlgParameters();\n\t\t\t\tString encryptionAlgorithm = getEncryptionAlgorithm(algorithmParameters, keyInfo.getAlgName());\n\t\t\t\tSecretKeyFactory keyFactory = SecretKeyFactory.getInstance(encryptionAlgorithm);\n\t\t\t\tSecretKey key = keyFactory.generateSecret(new PBEKeySpec(password.toCharArray()));\n\t\t\t\tCipher cipher = Cipher.getInstance(encryptionAlgorithm);\n\t\t\t\tcipher.init(Cipher.DECRYPT_MODE, key, algorithmParameters);\n\t\t\t\treturn keyInfo.getKeySpec(cipher);\n\t\t\t}\n\t\t\tcatch (IOException | GeneralSecurityException ex) {\n\t\t\t\tthrow new IllegalArgumentException(\"Error decrypting private key\", ex);\n\t\t\t}\n\t\t}\n\n\t\tprivate static String getEncryptionAlgorithm(@Nullable AlgorithmParameters algParameters, String algName) {\n\t\t\tif (algParameters != null && PBES2_ALGORITHM.equals(algName)) {\n\t\t\t\treturn algParameters.toString();\n\t\t\t}\n\t\t\treturn algName;\n\t\t}\n\n\t}\n\n\t/**\n\t * ANS.1 encoded object identifier.\n\t */\n\tstatic final class EncodedOid {\n\n\t\tstatic final EncodedOid OID_1_2_840_10040_4_1 = EncodedOid.of(\"2a8648ce380401\");","sourceCodeStart":446,"sourceCodeEnd":482,"githubUrl":"https://github.com/spring-projects/spring-boot/blob/270dfe353fb830fd69b823a8a859287ff103854b/buildpack/spring-boot-buildpack-platform/src/main/java/org/springframework/boot/buildpack/platform/docker/ssl/PemPrivateKeyParser.java#L446-L482","documentation":"Pkcs8PrivateKeyDecryptor.decrypt handles BEGIN ENCRYPTED PRIVATE KEY blocks. It builds EncryptedPrivateKeyInfo from the bytes, derives a PBE SecretKey from the supplied password, obtains a Cipher, and returns keyInfo.getKeySpec(cipher). The catch (IOException | GeneralSecurityException) wraps any failure as IllegalArgumentException. The most common cause is a wrong password; it can also be an unsupported encryption algorithm.","triggerScenarios":"createKeySpecForPkcs8Encrypted calls Pkcs8PrivateKeyDecryptor.decrypt(bytes, password). Failure occurs when: the password is wrong (Cipher.init or getKeySpec fails); the PBES2 algorithm in the key is not offered by the configured JCE provider; the encrypted key bytes are malformed; or password is null on an encrypted key (Assert.state at line 452 throws IllegalArgumentException before the try, with a different message).","commonSituations":"Wrong passphrase supplied at build time; key encrypted with an algorithm (e.g. PBES2 with AES-256-GCM) the JVM cannot service on a very old JDK without unlimited-crypto policy; corrupted encrypted key; password not propagated through the buildpack configuration.","solutions":["Supply the correct password (the parse(text, password) overload).","Verify the password decrypts the key out of band: `openssl pkey -in key.enc -passin pass:<pw>`.","Re-encrypt with a standard algorithm: `openssl pkcs8 -topk8 -in key.pem -out key.enc`.","On JDK 8u160 or older, install the JCE Unlimited Strength policy files; current JDKs ship with it by default."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"// Confirm the password decrypts the key out of band\nProcess p = new ProcessBuilder(\"openssl\", \"pkey\", \"-in\", keyPath.toString(),\n        \"-passin\", \"pass:\" + password, \"-noout\").redirectErrorStream(true).start();\nif (p.waitFor() != 0) {\n    throw new IllegalArgumentException(\"Wrong password or unsupported encryption for \" + keyPath);\n}","typeGuard":null,"tryCatchPattern":"try {\n    PemPrivateKeyParser.parse(text, password);\n} catch (IllegalStateException ex) {\n    Throwable c = ex.getCause();\n    if (c instanceof IllegalArgumentException\n            && \"Error decrypting private key\".equals(c.getMessage())) {\n        // prompt the user for the correct password and retry once\n    }\n    throw ex;\n}","preventionTips":["Verify the private key password in CI with `openssl pkey -in key.enc -passin pass:...`.","Prefer unencrypted keys when the secrets are already managed by a vault.","Re-encrypt with a standard PBES2 algorithm (`openssl pkcs8 -topk8`) for broad JVM compatibility."],"tags":["docker","ssl","private-key","encryption","pbe","buildpack"],"backgroundTag":null,"analyzedSha":"270dfe353fb830fd69b823a8a859287ff103854b","analyzedAt":"2026-08-11T19:42:06.541Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}