vectordotdev/vector · error

Invalid stored identity

Error message

Invalid stored identity

What it means

`identity_pem` serializes a stored TLS identity (OpenSSL `X509` cert and `PKey`) back to PEM bytes and panics with "Invalid stored identity" if `to_pem()` or `private_key_to_pem_pkcs8()` fails. The code assumes identity was validated at ingest time, so a failure here means the stored identity object is unusable — an internal invariant break.

Solutions

  1. Regenerate or re-export the certificate/key pair into standard PEM (X.509 cert + PKCS#8 key) and reconfigure TLS settings.
  2. Verify the configured `key` and `crt` files are a matching pair and parse cleanly with `openssl x509` / `openssl pkey`.
  3. Validate the identity at load time with the library's normal `TlsSettings::from_options` path instead of constructing `Identity` objects manually.
  4. If a specific key algorithm fails PKCS#8 export, convert the key (e.g. `openssl pkcs8 -topk8`) before use.
Defensive patterns

Strategy: validation

Validate before calling

// Validate the pair loads and re-serializes before configuring TLS
let cert = openssl::x509::X509::from_pem(&cert_pem)?;
let key = openssl::pkey::PKey::private_key_from_pem(&key_pem)?;
cert.to_pem().expect("cert serializes");
key.private_key_to_pem_pkcs8().expect("key serializes to PKCS#8");
// also check public keys match:
assert_eq!(cert.public_key()?.public_eq(&key), true, "cert/key mismatch");

Type guard

fn identity_is_serializable(cert: &openssl::x509::X509, key: &openssl::pkey::PKey<Private>) -> bool {
    cert.to_pem().is_ok() && key.private_key_to_pem_pkcs8().is_ok()
}

Try / catch

// The library panics; pre-validate in your own loader so identity_pem is never reached with a bad pair
fn load_identity(pem: &[u8], key: &[u8]) -> anyhow::Result<Identity> {
    let cert = X509::from_pem(pem)?;
    let key = PKey::private_key_from_pem(key)?;
    cert.to_pem().context("cert to_pem failed")?;
    key.private_key_to_pem_pkcs8().context("key to pkcs8 failed")?;
    Ok(Identity { cert, key, ca: None })
}

Prevention

When it happens

Trigger: Calling `TlsSettings::identity_pem()` when `identity.cert.to_pem()` or `identity.key.private_key_to_pem_pkcs8()` fails — e.g. the key/cert objects were constructed from malformed or mismatched data that bypassed ingest-time validation, or the key is an unsupported type for PKCS#8 serialization.

Common situations: TLS config files whose cert and key do not match or are in exotic formats that parsed but cannot re-serialize; identities loaded programmatically in tests without the usual validation path; OpenSSL backend limitations with certain key algorithms (e.g. unusual EC curves) failing PKCS#8 export.

Related errors


AI-assisted analysis of vectordotdev/vector@bdb87aeaa4 (2026-09-16). Data as JSON: /api/errors/4a4fbe06b6ce5a15. Report an issue: GitHub.

Appendix: source

Thrown at lib/vector-core/src/tls/settings.rs:244

    /// The configured SNI server name override, if any.
    pub fn server_name(&self) -> Option<&str> {
        self.server_name.as_deref()
    }

    /// Whether certificate hostname verification is enabled.
    pub fn verify_hostname(&self) -> bool {
        self.verify_hostname
    }

    /// Returns the identity as PEM encoded byte arrays
    ///
    /// # Panics
    ///
    /// Panics if the identity is missing, invalid, or the authorities to chain are invalid.
    pub fn identity_pem(&self) -> Option<(Vec<u8>, Vec<u8>)> {
        self.identity.as_ref().map(|identity| {
            // we have verified correct formatting at ingest time
            let mut cert = identity.cert.to_pem().expect("Invalid stored identity");
            let key = identity
                .key
                .private_key_to_pem_pkcs8()
                .expect("Invalid stored identity");
            if let Some(chain) = identity.ca.as_ref() {
                for authority in chain {
                    cert.extend(
                        authority
                            .to_pem()
                            .expect("Invalid stored identity chain certificate"),
                    );
                }
            }
            (cert, key)
        })
    }

    /// Returns the authorities as PEM data

View on GitHub (pinned to bdb87aeaa4)