IBM Support

IJ59137: PKCS12 AND CMS KEYSTORES PASSWORD CHANGE FAILS IN WEBSPHERE (TRADITIONAL) WITH IBMJCECCA AS THE FIRST SECURITY PROVIDER

Subscribe to this APAR

By subscribing, you receive periodic emails alerting you to the status of the APAR, along with a link to the fix after it becomes available. You can track this item individually or track all items by product.

Notify me when this APAR changes.

Notify me when an APAR for this component changes.

 

APAR status

  • Closed as program error.

Error description

  • Error Message: If a user tries to change a PKCS12 or CMS
    keystore using administrative functions in WebSphere
    (traditional) with IBMJCECCA as the first security provider,
    then the user may encounter the "Private key is not encoded as
    PKCS#8" error for PKCS12 and "java.io.IOException:
    PrivateKeyInfo parsing error." error for CMS keystore.
    .
    Stack Trace:
    --- PKCS12 Error ---
    
    com.ibm.websphere.management.cmdframework.CommandException:
    Private key is not encodedas PKCS#8
    at com.ibm.ws.ssl.commands.keyStores.ChangeMultipleKeyStorePass
    words.beforeStepsExecuted(ChangeMultipleKeyStorePasswords.java:
    152)
    at com.ibm.websphere.management.cmdframework.provider.AbstractT
    askCommand.executeReal(AbstractTaskCommand.java:835)
    
    at
    com.ibm.websphere.management.cmdframework.provider.AbstractTask
    Command.execute(AbstractTaskCommand.java:807)
    
    at
    com.ibm.ws.management.cmdframework.impl.RemoteCommandMgrImpl.ex
    ecute(RemoteCommandMgrImpl.java:370)
    
    at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
    at
    sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccesso
    rImpl.java:90)
    
    at
    sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMetho
    dAccessorImpl.java:55)
    
    at java.lang.reflect.Method.invoke(Method.java:508)
    
    at sun.reflect.misc.Trampoline.invoke(MethodUtil.java:83)
    
    atsun.reflect.GeneratedMethodAccessor60.invoke(Unknown Source)
    ...
    Caused by: com.ibm.websphere.crypto.KeyException: Private key is
    
    
    
    not encodedas PKCS#8
    at com.ibm.ws.ssl.config.WSKeyStore.invokeKeyStoreCommand(WSKey
    Store.java:2313)
    
    at
    com.ibm.ws.ssl.config.WSKeyStoreRemotable.invokeKeyStoreCommand
    (WSKeyStoreRemotable.java:275)
    
    at
    com.ibm.ws.ssl.commands.keyStores.KeyStoreHelper.changePassword
    PKCS12(KeyStoreHelper.java:983)
    
    at
    com.ibm.ws.ssl.commands.keyStores.ChangeMultipleKeyStorePasswor
    ds.changeKSPasswords(ChangeMultipleKeyStorePasswords.java:196)
    at
    com.ibm.ws.ssl.commands.keyStores.ChangeMultipleKeyStorePasswor
    ds.beforeStepsExecuted(ChangeMultipleKeyStorePasswords.java:146)
    
    
    
    Caused by: java.security.KeyStoreException: Private key is not
    encodedas PKCS#8
    at com.ibm.crypto.provider.PKCS12KeyStoreOracle.engineSetKeyEnt
    ry(PKCS12KeyStoreOracle.java:1046)
    
    at java.security.KeyStore.setKeyEntry(KeyStore.java:1155)
    
    at
    com.ibm.ws.ssl.config.WSKeyStore.invokeKeyStoreCommand(WSKeySto
    re.java:1776)   ... 29 more
    Caused by: java.security.KeyStoreException: Private key is not
    encoded as PKCS#8
    at com.ibm.crypto.provider.PKCS12KeyStoreOracle.a(PKCS12KeySto
    reOracle.java:1030)
    
    at
    com.ibm.crypto.provider.PKCS12KeyStoreOracle.engineSetKeyEntry(
    PKCS12KeyStoreOracle.java:348)  ... 31 more
    Caused by: java.security.KeyStoreException: Private key is not
    encodedas PKCS#8
    at
    com.ibm.crypto.provider.PKCS12KeyStoreOracle.a(PKCS12KeyStoreOr
    acle.java:802)   ... 32 more
    
    --- CMS Error ---
    
    com.ibm.websphere.management.cmdframework.CommandException
    java.lang.Exception: java.lang.Exception: PrivateKeyInfo parsing
    
    error.   at
    com.ibm.security.cmskeystore.CMSKeyStoreSpi.engineStore(C
    MSKeyStoreSpi.java)   at
    java.security.KeyStore.store(KeyStore.java)
    .
    

Local fix

  • Remove IBMJCECCA from the provider list to change PKCS12 and CMS
    
    
    
    
    keystore password in WebSphere (traditional)
    

Problem summary

  • If a user tries to change a PKCS12 or CMS keystore using
    administrative functions in WebSphere (traditional) with
    IBMJCECCA as the first security provider, then the user may
    encounter the "Private key is not encoded as PKCS#8 error
    for PKCS12" and "java.io.IOException: PrivateKeyInfo parsing
    error." error for CMS keystore.
    

Problem conclusion

Temporary fix

Comments

APAR Information

  • APAR number

    IJ59137

  • Reported component name

    SECURITY

  • Reported component ID

    620700125

  • Reported release

    270

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2026-07-24

  • Closed date

    2026-07-24

  • Last modified date

    2026-07-27

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    SECURITY

  • Fixed component ID

    620700125

Applicable component levels

[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSNVBF","label":"Runtimes for Java Technology"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"270","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}}]

Document Information

Modified date:
27 July 2026