# Logstash 1.5.4 : No password supplied for PKCS#12 KeyStore

**URL:** <https://discuss.elastic.co/t/logstash-1-5-4-no-password-supplied-for-pkcs-12-keystore/127697>\
**Category:** Logstash\
**Created:** [April 11, 2018, 7:32pm UTC](https://discuss.elastic.co/t/logstash-1-5-4-no-password-supplied-for-pkcs-12-keystore/127697 "2018-04-11T19:32:24Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![meghnatolani](https://avatars.discourse-cdn.com/v4/letter/m/a5b964/32.png) [@meghnatolani](https://discuss.elastic.co/u/meghnatolani)\
**Post date:** [April 11, 2018, 7:32pm UTC](https://discuss.elastic.co/t/logstash-1-5-4-no-password-supplied-for-pkcs-12-keystore/127697/1 "2018-04-11T19:32:24Z")

</div>

Hi,

I am using logstash version 1.5.4 I am getting the bellow error -

```
WARNING: Default JAVA_OPTS will be overridden by the JAVA_OPTS defined in the environment. Environment JAVA_OPTS are -Djava.io.tmpdir=/var/lib/logstash 
OpenSSL::X509::StoreError: setting default path failed: **No password supplied for PKCS#12 KeyStore**. 
set_default_paths at org/jruby/ext/openssl/X509Store.java:185 
(root) at /opt/logstash/vendor/jruby/lib/ruby/shared/jopenssl/load.rb:22 
require at org/jruby/RubyKernel.java:1072 
(root) at /opt/logstash/vendor/jruby/lib/ruby/shared/openssl.rb:1 
require at org/jruby/RubyKernel.java:1072 
(root) at /opt/logstash/vendor/jruby/lib/ruby/shared/openssl.rb:1 
require at org/jruby/RubyKernel.java:1072 
(root) at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.4-java/lib/logstash/patches/stronger_openssl_defaults.rb:1 
require at org/jruby/RubyKernel.java:1072 
(root) at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.4-java/lib/logstash/patches/stronger_openssl_defaults.rb:2 
require at org/jruby/RubyKernel.java:1072 
(root) at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.4-java/lib/logstash/patches.rb:1 
require at org/jruby/RubyKernel.java:1072 
(root) at /opt/logstash/lib/bootstrap/environment.rb:48

```

Can anyone help please?

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [April 12, 2018, 3:59am UTC](https://discuss.elastic.co/t/logstash-1-5-4-no-password-supplied-for-pkcs-12-keystore/127697/2 "2018-04-12T03:59:10Z")

</div>

My searches seem to indicate that others had this trouble running old versions of Logstash with a Java JDK that was newer than the Java available when that old version of Logstash was built:

> <https://github.com/logstash-plugins/logstash-filter-translate/issues/20>

- what version of Java are you running?

```auto
java -version

```

- what is your `JAVA_HOME`?

```auto
echo $JAVA_HOME

```

---

<div class="post-metadata">

**Author:** ![meghnatolani](https://avatars.discourse-cdn.com/v4/letter/m/a5b964/32.png) [@meghnatolani](https://discuss.elastic.co/u/meghnatolani)\
**Post date:** [April 12, 2018, 5:31pm UTC](https://discuss.elastic.co/t/logstash-1-5-4-no-password-supplied-for-pkcs-12-keystore/127697/3 "2018-04-12T17:31:45Z")

</div>

java -version

```
    openjdk version "1.8.0_161"
    OpenJDK Runtime Environment (build 1.8.0_161-b14)
    OpenJDK 64-Bit Server VM (build 25.161-b14, mixed mode)

```

no output when running echo $JAVA\_HOME. $JAVA\_HOME is not set.

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [April 12, 2018, 11:08pm UTC](https://discuss.elastic.co/t/logstash-1-5-4-no-password-supplied-for-pkcs-12-keystore/127697/4 "2018-04-12T23:08:26Z")

</div>

Logstash 1.x is relatively out-of-date, and it runs on a version of JRuby that reached end-of-life [on 2016-11-21](https://github.com/jruby/jruby/issues/4112#issuecomment-346190422) with dependencies that are similarly end-of-life or may have diverged in the years since its release; I'd recommend using a newer Logstash if you're able -- the current release is 6.x, and includes significant new features and improvements.

* * *

I did a little sleuthing, and it looks like older versions of JRuby made an assumption in their OpenSSL implementation that caused the above error; it appears as though `KeyStore#getDefaultType` was not a reliable way to get the Java Key Store it needed, and well-behaved JVMs could reasonably set a different value as the default. My guess here is that either your JVM is configured with a different default, or the OpenJDK variant is.

To get [the fix](https://github.com/jruby/jruby-openssl/commit/bb8d0743ddd31a5417ab38aa9c25d1e6403c9243), you will need to install at least version 0.9.14 of the `jruby-openssl` gem to _override_ the implementation that shipped with jruby (it appears as though [`jruby-openssl-0.9.21`](https://rubygems.org/gems/jruby-openssl/versions/0.9.21-java) is the most recent version that is [backwards-compatible with JRuby 1.7.x](https://github.com/jruby/jruby-openssl#compatibility)).

You _may_ be able to install the one gem by adding it to the runtime dependencies in the `logstash-core.gemspec` file in the block that selects for `java`:

```auto
    # pin jruby-openssl implementation to most recent compatible version
    gem.add_runtime_dependency "jruby-openssl", "~> 0.9.21"

```

And then run the vendored `bundle` executable to tell it to resolve dependencies:

```auto
cd $logstash_home
bin/bundle install 

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 10, 2018, 11:08pm UTC](https://discuss.elastic.co/t/logstash-1-5-4-no-password-supplied-for-pkcs-12-keystore/127697/5 "2018-05-10T23:08:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
