https://bz.apache.org/bugzilla/show_bug.cgi?id=64614

            Bug ID: 64614
           Summary: tomcat doesn't work with JSSE FIPS-compliant with NSS
           Product: Tomcat 9
           Version: 9.0.x
          Hardware: PC
                OS: Linux
            Status: NEW
          Severity: normal
          Priority: P2
         Component: Connectors
          Assignee: dev@tomcat.apache.org
          Reporter: jfcl...@gmail.com
  Target Milestone: -----

When configured with FIPS with NSS The connector gives the following exception:
20-Jul-2020 09:11:03.863 SEVERE [main]
org.apache.catalina.util.LifecycleBase.handleSubClassException Failed to
initialize component [Connector[HTTP/1.1-8443]]
        org.apache.catalina.LifecycleException: Protocol handler initialization
failed
                at
org.apache.catalina.connector.Connector.initInternal(Connector.java:1042)
                at
org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:136)
                at
org.apache.catalina.core.StandardService.initInternal(StandardService.java:533)
                at
org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:136)
                at
org.apache.catalina.core.StandardServer.initInternal(StandardServer.java:1057)
                at
org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:136)
                at org.apache.catalina.startup.Catalina.load(Catalina.java:690)
                at org.apache.catalina.startup.Catalina.load(Catalina.java:712)
                at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
                at
sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
                at
sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
                at java.lang.reflect.Method.invoke(Method.java:498)
                at
org.apache.catalina.startup.Bootstrap.load(Bootstrap.java:302)
                at
org.apache.catalina.startup.Bootstrap.main(Bootstrap.java:472)
        Caused by: java.lang.IllegalArgumentException: FIPS mode: only SunJSSE
KeyManagers may be used
                at
org.apache.tomcat.util.net.AbstractJsseEndpoint.createSSLContext(AbstractJsseEndpoint.java:99)
                at
org.apache.tomcat.util.net.AbstractJsseEndpoint.initialiseSsl(AbstractJsseEndpoint.java:71)
                at
org.apache.tomcat.util.net.NioEndpoint.bind(NioEndpoint.java:216)
                at
org.apache.tomcat.util.net.AbstractEndpoint.bindWithCleanup(AbstractEndpoint.java:1141)
                at
org.apache.tomcat.util.net.AbstractEndpoint.init(AbstractEndpoint.java:1154)
                at
org.apache.coyote.AbstractProtocol.init(AbstractProtocol.java:581)
                at
org.apache.coyote.http11.AbstractHttp11Protocol.init(AbstractHttp11Protocol.java:74)
                at
org.apache.catalina.connector.Connector.initInternal(Connector.java:1039)
                ... 13 more
        Caused by: java.security.KeyManagementException: FIPS mode: only
SunJSSE KeyManagers may be used
                at
sun.security.ssl.SSLContextImpl.chooseKeyManager(SSLContextImpl.java:154)
                at
sun.security.ssl.SSLContextImpl.engineInit(SSLContextImpl.java:71)
                at javax.net.ssl.SSLContext.init(SSLContext.java:282)
                at
org.apache.tomcat.util.net.jsse.JSSESSLContext.init(JSSESSLContext.java:61)
                at
org.apache.tomcat.util.net.SSLUtilBase.createSSLContext(SSLUtilBase.java:246)
                at
org.apache.tomcat.util.net.AbstractJsseEndpoint.createSSLContext(AbstractJsseEndpoint.java:97)
                ... 20 more

-- 
You are receiving this mail because:
You are the assignee for the bug.
---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org

Reply via email to