elastic/elasticsearch · error · IOException

Malformed PEM file, DSA Parameters footer is missing

Error message

Malformed PEM file, DSA Parameters footer is missing

What it means

Thrown by removeDsaHeaders when the file starts with '-----BEGIN DSA PARAMETERS-----' but the matching '-----END DSA PARAMETERS-----' line is never found (EOF reached) or the matched line is incorrect. Mirrors the EC PARAMETERS check but for DSA keys produced by OpenSSL's 'dsa' tooling.

Source

Thrown at libs/ssl-config/src/main/java/org/elasticsearch/common/ssl/PemUtils.java:205

        return bReader;
    }

    /**
     * Removes the DSA Params Headers that OpenSSL adds to DSA private keys as the information in them
     * is redundant
     *
     * @throws IOException if the EC Parameter footer is missing
     */
    private static BufferedReader removeDsaHeaders(BufferedReader bReader) throws IOException {
        String line = bReader.readLine();
        while (line != null) {
            if (OPENSSL_DSA_PARAMS_FOOTER.equals(line.trim())) {
                break;
            }
            line = bReader.readLine();
        }
        if (null == line || OPENSSL_DSA_PARAMS_FOOTER.equals(line.trim()) == false) {
            throw new IOException("Malformed PEM file, DSA Parameters footer is missing");
        }
        // Verify that the key starts with the correct header before passing it to parseOpenSslDsa
        if (OPENSSL_DSA_HEADER.equals(bReader.readLine()) == false) {
            throw new IOException("Malformed PEM file, DSA Key header is missing");
        }
        return bReader;
    }

    /**
     * Creates a {@link PrivateKey} from the contents of {@code bReader} that contains an plaintext private key encoded in
     * PKCS#8
     *
     * @param bReader the {@link BufferedReader} containing the key file contents
     * @return {@link PrivateKey}
     * @throws IOException              if the file can't be read
     * @throws GeneralSecurityException if the private key can't be generated from the {@link PKCS8EncodedKeySpec}
     */
    private static PrivateKey parsePKCS8(BufferedReader bReader) throws IOException, GeneralSecurityException {

View on GitHub (pinned to db6a809a66)

Solutions

  1. Verify the file contains both '-----BEGIN DSA PARAMETERS-----' and '-----END DSA PARAMETERS-----' as standalone lines.
  2. Regenerate the DSA key: 'openssl dsaparam -out dsaparam.pem 2048 && openssl gendsa -out dsa-key.pem dsaparam.pem'.
  3. Re-transfer the file in binary mode and confirm checksums.
Defensive patterns

Strategy: validation

Validate before calling

// Reuse the matching-footer helper from 801 with begin='-----BEGIN DSA PARAMETERS-----' and end='-----END DSA PARAMETERS-----'.

Try / catch

try { PemUtils.readPrivateKey(path, passwordSupplier); }
catch (IOException e) { if (e.getMessage().contains("DSA Parameters footer is missing")) { /* re-issue key */ } else throw e; }

Prevention

When it happens

Trigger: Loading a PEM that begins with '-----BEGIN DSA PARAMETERS-----' but is truncated before the '-----END DSA PARAMETERS-----' line; the footer was edited or removed; the file is a parameters-only file with no DSA PARAMETERS footer at all.

Common situations: DSA parameters file truncated during transfer; footer stripped by a template engine; mismatched BEGIN/END from manual editing; legacy DSA keys generated by very old OpenSSL that omit the footer in some configurations.

Understand the failure class

Related errors


AI-assisted analysis of elastic/elasticsearch@db6a809a66 (2026-08-12). Data as JSON: /api/errors/8b32e30d333af17b. Report an issue: GitHub.