[jboss-jira] [JBoss JIRA] (WFLY-7158) Working with multiple keys in key store

Jan Kalina (JIRA) issues at jboss.org
Mon Jan 23 05:40:01 EST 2017


    [ https://issues.jboss.org/browse/WFLY-7158?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13352061#comment-13352061 ] 

Jan Kalina commented on WFLY-7158:
----------------------------------

As discussed with [~pskopek], for the future it should work by this way:
{code:xml}
<key-manager name="ServerKeyManager" algorithm="SunX509">
  <credential-reference store="keyskeystore" alias="mykey">
    <credential-store store="passwordskeystore" alias="mykey-pwd"/>
  </credential-reference>
</key-manager>
{code}
(key-store "keyskeystore" contains SSL key "mykey", which is encrypted by password, which is stored in key-store "passwordskeystore" in alias "mykey-pwd")
*But we dont support this (credential-reference referencing another credential-reference) for now.*
The best way for now will be to keep user to define filtering-key-store and reference it from key-manager.

> Working with multiple keys in key store
> ---------------------------------------
>
>                 Key: WFLY-7158
>                 URL: https://issues.jboss.org/browse/WFLY-7158
>             Project: WildFly
>          Issue Type: Bug
>          Components: Security
>            Reporter: Martin Choma
>            Assignee: Jan Kalina
>            Priority: Critical
>             Fix For: 11.0.0.Alpha1
>
>
> In case when 2 keys are present in keystore, then alias-filter (filtering into single key) on key-store resource has to be specified, otherwise key-manager can't be created. If user want to use keystore with multiple keys, user has to configure multiple key-store elements with specified alias-filter (filtering into single key).
> That is pretty inconvinient. Probably introducing *alias attribute on key-manager* would be more intuitive solution to this situation.
> {code}
> /subsystem=elytron/key-managers=server:add(key-store=server,algorithm="SunX509",password=key-password)
> {code}



--
This message was sent by Atlassian JIRA
(v7.2.3#72005)



More information about the jboss-jira mailing list