{"record":{"id":"d7063da8c3963baf","repo":"spring-projects/spring-boot","slug":"missing-private-key-or-unrecognized-format","errorCode":null,"errorMessage":"Missing private key or unrecognized format","messagePattern":"Missing private key or unrecognized format","errorType":"exception","errorClass":"IllegalStateException","httpStatus":null,"severity":"error","filePath":"buildpack/spring-boot-buildpack-platform/src/main/java/org/springframework/boot/buildpack/platform/docker/ssl/PemPrivateKeyParser.java","lineNumber":220,"sourceCode":"\t * @param password the password used to decrypt an encrypted private key\n\t * @return the parsed private key\n\t */\n\tstatic @Nullable PrivateKey parse(@Nullable String text, @Nullable String password) {\n\t\tif (text == null) {\n\t\t\treturn null;\n\t\t}\n\t\ttry {\n\t\t\tfor (PemParser pemParser : PEM_PARSERS) {\n\t\t\t\tPrivateKey privateKey = pemParser.parse(text, password);\n\t\t\t\tif (privateKey != null) {\n\t\t\t\t\treturn privateKey;\n\t\t\t\t}\n\t\t\t}\n\t\t}\n\t\tcatch (Exception ex) {\n\t\t\tthrow new IllegalStateException(\"Error loading private key file: \" + ex.getMessage(), ex);\n\t\t}\n\t\tthrow new IllegalStateException(\"Missing private key or unrecognized format\");\n\t}\n\n\t/**\n\t * Parser for a specific PEM format.\n\t */\n\tprivate static class PemParser {\n\n\t\tprivate final Pattern pattern;\n\n\t\tprivate final BiFunction<byte[], @Nullable String, PKCS8EncodedKeySpec> keySpecFactory;\n\n\t\tprivate final String[] algorithms;\n\n\t\tPemParser(String header, String footer,\n\t\t\t\tBiFunction<byte[], @Nullable String, PKCS8EncodedKeySpec> keySpecFactory, String... algorithms) {\n\t\t\tthis.pattern = Pattern.compile(header + BASE64_TEXT + footer, Pattern.CASE_INSENSITIVE);\n\t\t\tthis.keySpecFactory = keySpecFactory;\n\t\t\tthis.algorithms = algorithms;","sourceCodeStart":202,"sourceCodeEnd":238,"githubUrl":"https://github.com/spring-projects/spring-boot/blob/270dfe353fb830fd69b823a8a859287ff103854b/buildpack/spring-boot-buildpack-platform/src/main/java/org/springframework/boot/buildpack/platform/docker/ssl/PemPrivateKeyParser.java#L202-L238","documentation":"All four PEM_PARSERS returned null because none of their header regexes (PKCS1 RSA, SEC1 EC, PKCS8, encrypted PKCS8) matched the input text. parse then falls through to line 220 and throws IllegalStateException. The file is present and non-null but contains no recognizable PEM private key block.","triggerScenarios":"parse(text, password) is called with a non-null text whose contents contain no BEGIN ... PRIVATE KEY header that any parser recognizes: a binary DER key, a certificate, a public key, an OpenSSH-format key (BEGIN OPENSSH PRIVATE KEY), or an empty/garbage file.","commonSituations":"Pointing keyPath at a .crt/.pub file; a binary .der private key; an OpenSSH-format Ed25519/RSA key; an empty file; a PKCS7/PFX bundle.","solutions":["Confirm the file actually contains a private key: look for a `-----BEGIN ... PRIVATE KEY-----` line.","Convert a DER key to PEM: `openssl pkey -in der-key.der -out key.pem`.","Convert an OpenSSH key to PEM: `ssh-keygen -p -m PEM -f id_ed25519`, or `openssl pkey -in id_ed25519 -out key.pem`.","Convert a PKCS8 unencrypted key: `openssl pkcs8 -topk8 -nocrypt -in key.pem -out key-pkcs8.pem`."],"exampleFix":"// before: pointing keyPath at an OpenSSH-format key\nPath keyPath = Path.of(\"id_ed25519\"); // -----BEGIN OPENSSH PRIVATE KEY-----\n// after: convert first, then point at standard PEM\n//   $ ssh-keygen -p -m PEM -f id_ed25519\nPath keyPath = Path.of(\"id_ed25519\"); // now -----BEGIN PRIVATE KEY-----","handlingStrategy":"validation","validationCode":"// Reject non-PEM or unsupported private key files before parsing\nString text = Files.readString(keyPath);\nboolean hasPemHeader = text.contains(\"-----BEGIN RSA PRIVATE KEY-----\")\n        || text.contains(\"-----BEGIN EC PRIVATE KEY-----\")\n        || text.contains(\"-----BEGIN PRIVATE KEY-----\")\n        || text.contains(\"-----BEGIN ENCRYPTED PRIVATE KEY-----\");\nif (!hasPemHeader) {\n    throw new IllegalArgumentException(\n        keyPath + \" is not a recognized PEM private key. Convert with: \"\n        + \"openssl pkcs8 -topk8 -nocrypt -in <key> -out <key>.pem\");\n}","typeGuard":null,"tryCatchPattern":"try {\n    PemPrivateKeyParser.parse(text, password);\n} catch (IllegalStateException ex) {\n    if (ex.getMessage().equals(\"Missing private key or unrecognized format\")) {\n        // hint: convert OpenSSH/DER keys to standard PEM PKCS8\n    }\n    throw ex;\n}","preventionTips":["Convert all private keys to standard PEM PKCS8 upfront (`openssl pkcs8 -topk8 -nocrypt`).","Convert OpenSSH keys with `ssh-keygen -p -m PEM -f <key>`.","Distinguish cert files (.crt/.pub) from key files in configuration."],"tags":["docker","ssl","private-key","pem","buildpack"],"backgroundTag":null,"analyzedSha":"270dfe353fb830fd69b823a8a859287ff103854b","analyzedAt":"2026-08-11T19:42:06.541Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}