vectordotdev/vector · error
Invalid stored identity
Error message
Invalid stored identity
What it means
`identity_pem` serializes a stored TLS identity (OpenSSL `X509` cert and `PKey`) back to PEM bytes and panics with "Invalid stored identity" if `to_pem()` or `private_key_to_pem_pkcs8()` fails. The code assumes identity was validated at ingest time, so a failure here means the stored identity object is unusable — an internal invariant break.
Solutions
- Regenerate or re-export the certificate/key pair into standard PEM (X.509 cert + PKCS#8 key) and reconfigure TLS settings.
- Verify the configured `key` and `crt` files are a matching pair and parse cleanly with `openssl x509` / `openssl pkey`.
- Validate the identity at load time with the library's normal `TlsSettings::from_options` path instead of constructing `Identity` objects manually.
- If a specific key algorithm fails PKCS#8 export, convert the key (e.g. `openssl pkcs8 -topk8`) before use.
Defensive patterns
Strategy: validation
Validate before calling
// Validate the pair loads and re-serializes before configuring TLS
let cert = openssl::x509::X509::from_pem(&cert_pem)?;
let key = openssl::pkey::PKey::private_key_from_pem(&key_pem)?;
cert.to_pem().expect("cert serializes");
key.private_key_to_pem_pkcs8().expect("key serializes to PKCS#8");
// also check public keys match:
assert_eq!(cert.public_key()?.public_eq(&key), true, "cert/key mismatch"); Type guard
fn identity_is_serializable(cert: &openssl::x509::X509, key: &openssl::pkey::PKey<Private>) -> bool {
cert.to_pem().is_ok() && key.private_key_to_pem_pkcs8().is_ok()
} Try / catch
// The library panics; pre-validate in your own loader so identity_pem is never reached with a bad pair
fn load_identity(pem: &[u8], key: &[u8]) -> anyhow::Result<Identity> {
let cert = X509::from_pem(pem)?;
let key = PKey::private_key_from_pem(key)?;
cert.to_pem().context("cert to_pem failed")?;
key.private_key_to_pem_pkcs8().context("key to pkcs8 failed")?;
Ok(Identity { cert, key, ca: None })
} Prevention
- Always load TLS identity through TlsSettings::from_options so ingest-time validation runs.
- Verify cert and key match (public_eq check) before storing the identity.
- Convert keys to PKCS#8 up front (openssl pkcs8 -topk8) so private_key_to_pem_pkcs8 cannot fail.
- Test TLS config files at startup with openssl x509/openssl pkey rather than discovering failures mid-connection.
When it happens
Trigger: Calling `TlsSettings::identity_pem()` when `identity.cert.to_pem()` or `identity.key.private_key_to_pem_pkcs8()` fails — e.g. the key/cert objects were constructed from malformed or mismatched data that bypassed ingest-time validation, or the key is an unsupported type for PKCS#8 serialization.
Common situations: TLS config files whose cert and key do not match or are in exotic formats that parsed but cannot re-serialize; identities loaded programmatically in tests without the usual validation path; OpenSSL backend limitations with certain key algorithms (e.g. unusual EC curves) failing PKCS#8 export.
Related errors
- Building HTTP client failed
- HTTPS initialization failed
- Invalid stored authority certificate
- Invalid stored identity chain certificate
- mutex poisoned
AI-assisted analysis of vectordotdev/vector@bdb87aeaa4 (2026-09-16).
Data as JSON: /api/errors/4a4fbe06b6ce5a15.
Report an issue: GitHub.
Appendix: source
Thrown at lib/vector-core/src/tls/settings.rs:244
/// The configured SNI server name override, if any.
pub fn server_name(&self) -> Option<&str> {
self.server_name.as_deref()
}
/// Whether certificate hostname verification is enabled.
pub fn verify_hostname(&self) -> bool {
self.verify_hostname
}
/// Returns the identity as PEM encoded byte arrays
///
/// # Panics
///
/// Panics if the identity is missing, invalid, or the authorities to chain are invalid.
pub fn identity_pem(&self) -> Option<(Vec<u8>, Vec<u8>)> {
self.identity.as_ref().map(|identity| {
// we have verified correct formatting at ingest time
let mut cert = identity.cert.to_pem().expect("Invalid stored identity");
let key = identity
.key
.private_key_to_pem_pkcs8()
.expect("Invalid stored identity");
if let Some(chain) = identity.ca.as_ref() {
for authority in chain {
cert.extend(
authority
.to_pem()
.expect("Invalid stored identity chain certificate"),
);
}
}
(cert, key)
})
}
/// Returns the authorities as PEM dataView on GitHub (pinned to bdb87aeaa4)