APAR status
Closed as program error.
Error description
Error Message: If a user tries to change a PKCS12 or CMS keystore using administrative functions in WebSphere (traditional) with IBMJCECCA as the first security provider, then the user may encounter the "Private key is not encoded as PKCS#8" error for PKCS12 and "java.io.IOException: PrivateKeyInfo parsing error." error for CMS keystore</errorMessage> <stackTrace>com.ibm.websphere.management.cmdframework.CommandEx ception:Private key is not encodedas PKCS#8 at com.ibm.ws.ssl.commands.keyStores.ChangeMultipleKeyStoreP asswords.beforeStepsExecuted(ChangeMultipleKeyStorePasswords.ja va:152) at com.ibm.websphere.management.cmdframework.provider.Abstra ctTaskCommand.executeReal(AbstractTaskCommand.java:835) at com.ibm.websphere.management.cmdframework.provider.Abstra ctTaskCommand.execute(AbstractTaskCommand.java:807) at com.ibm.ws.management.cmdframework.impl.RemoteCommandMgrI mpl.execute(RemoteCommandMgrImpl.java:370) at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodA ccessorImpl.java:90) at sun.reflect.DelegatingMethodAccessorImpl.invoke(Delegatin gMethodAccessorImpl.java:55) at java.lang.reflect.Method.invoke(Method.java:508) at sun.reflect.misc.Trampoline.invoke(MethodUtil.java:83) at sun.reflect.GeneratedMethodAccessor60.invoke(Unknown Source) ... Caused by: com.ibm.websphere.crypto.KeyException: Private key is not encodedas PKCS#8 at com.ibm.ws.ssl.config.WSKeyStore.invokeKeyStoreCommand(WS KeyStore.java:2313) at com.ibm.ws.ssl.config.WSKeyStoreRemotable.invokeKeyStoreC ommand(WSKeyStoreRemotable.java:275) at com.ibm.ws.ssl.commands.keyStores.KeyStoreHelper.changePa sswordPKCS12(KeyStoreHelper.java:983) at com.ibm.ws.ssl.commands.keyStores.ChangeMultipleKeyStoreP asswords.changeKSPasswords(ChangeMultipleKeyStorePasswords.java :196) at com.ibm.ws.ssl.commands.keyStores.ChangeMultipleKeyStoreP asswords.beforeStepsExecuted(ChangeMultipleKeyStorePasswords.ja va:146) ... 25 more Caused by: java.security.KeyStoreException: Private key is not encodedas PKCS#8 at com.ibm.crypto.provider.PKCS12KeyStoreOracle.engineSetKey Entry(PKCS12KeyStoreOracle.java:1046) at java.security.KeyStore.setKeyEntry(KeyStore.java:1155) at com.ibm.ws.ssl.config.WSKeyStore.invokeKeyStoreCommand(WS KeyStore.java:1776) ... 29 more Caused by: java.security.KeyStoreException: Private key is not encodedas PKCS#8 at com.ibm.crypto.provider.PKCS12KeyStoreOracle.a(PKCS12KeyS toreOracle.java:1030) at com.ibm.crypto.provider.PKCS12KeyStoreOracle.engineSetKey Entry(PKCS12KeyStoreOracle.java:348) ... 31 more Caused by: java.security.KeyStoreException: Private key is not encodedas PKCS#8 at com.ibm.crypto.provider.PKCS12KeyStoreOracle.a(PKCS12KeyS toreOracle.java:802) ... 32 more</stackTrace> com.ibm.websphere.management.cmdframework.CommandException java.lang.Exception: java.lang.Exception: PrivateKeyInfo parsing error. at com.ibm.security.cmskeystore.CMSKeyStoreSpi.engineStore(CMSK eyStoreSpi.java) at java.security.KeyStore.store(KeyStore.java)
Local fix
Remove IBMJCECCA from the provider list to change PKCS12 keystore password in WebSphere (traditional)
Problem summary
If a user tries to change a PKCS12 or CMS keystore using administrative functions in WebSphere (traditional) with IBMJCECCA as the first security provider, then the user may encounter the "Private key is not encoded as PKCS#8" error for PKCS12 and "java.io.IOException: PrivateKeyInfo parsing error." error for CMS keystore
Problem conclusion
The PKCS12 and CMS keystore providers were adjusted to use the correct security provider to load PKCS12 and CMS keystores. . This APAR will be fixed in the following Releases: . IBM Semeru Runtimes IBM SDK, Java Technology Edition 8 SR8 FP70 (8.0.8.70) . Downloads and supplementary documentation can be found at the following locations: - For the z/OS operating system: - Java SDK Products on z/OS https://www.ibm.com/support/pages/java-sdk-products-zos
Temporary fix
Comments
APAR Information
APAR number
PH71568
Reported component name
JAVA Z/OS 64
Reported component ID
620700104
Reported release
800
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2026-06-02
Closed date
2026-06-02
Last modified date
2026-06-24
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
JAVA Z/OS 64
Fixed component ID
620700104
Applicable component levels
[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSNVBF","label":"Runtimes for Java Technology"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"800","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}}]
Document Information
Modified date:
24 June 2026