Skip to content

Fix four-arg CertificateBundle.of private key type argument - #1075

Open
arimu1 wants to merge 1 commit into
spring-projects:mainfrom
arimu1:fix/certificate-bundle-of-private-key-type-1047
Open

arimu1 wants to merge 1 commit into
spring-projects:mainfrom
arimu1:fix/certificate-bundle-of-private-key-type-1047

Conversation

@arimu1

@arimu1 arimu1 commented Sep 12, 2026 •

Copy link
Copy Markdown

Summary

  • Fix the four-argument CertificateBundle.of(String, String, String, String) factory so it passes null for privateKeyType instead of duplicating the PEM private key string.
  • Extend CertificateBundleUnitTests to assert getPrivateKeyType() is null for the four-arg factory and that the five-arg overload still parses RSA keys correctly.

Problem

The four-arg of() method incorrectly passed privateKey as both the private key and privateKeyType constructor arguments. Callers that later invoked getPrivateKeySpec() hit IllegalArgumentException because the key type was PEM material rather than rsa or ec.

Test plan

  • mvn -pl spring-vault-core -am test -Dtest=CertificateBundleUnitTests -DfailIfNoTests=false (Temurin 21)

Fixes #1047

Pass null for privateKeyType in the four-argument factory so the PEM
private key is not stored as the key type, which broke getPrivateKeySpec().

Fixes spring-projects#1047

Signed-off-by: arimu1 <19286898+arimu1@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CertificateBundle.of uses private key value instead of type, which causes exception throwing when trying to access private key

1 participant