ppkarwasz opened a new issue, #4346:
URL: https://github.com/apache/logging-log4j2/issues/4346

   ## Description
   
   `SslConfigurationFactory.createSslConfiguration` throws a 
`NullPointerException`
   when a trust store (or key store) location is configured without a store 
type.
   
   If `log4j2.trustStoreLocation` is set and `log4j2.trustStoreKeyStoreType` is 
not,
   `getPassword(password, storeType)` is called with a `null` type, outside the 
`try` block,
   and fails on `keyStoreType.equals(StoreConfiguration.JKS)`.
   The same happens for `log4j2.keyStoreLocation` without `log4j2.keyStoreType`.
   
   `AbstractKeyStoreConfiguration` would otherwise fall back to the default 
store type,
   so a location without a type should work.
   
   Expected behavior: default a missing type (e.g. to 
`KeyStore.getDefaultType()` or the Log4j default)
   before calling `getPassword`, or move the call inside the `try` block.
   
   ## Configuration
   
   **Version:** 2.26.1 (and `2.x` at `d631e82`)
   
   **Operating system:** any
   
   **JDK:** any
   
   ## Logs
   
   A `NullPointerException` thrown from `SslConfigurationFactory.getPassword`, 
called by `createSslConfiguration`.
   
   ## Reproduction
   
   Run with `-Dlog4j2.trustStoreLocation=/path/to/truststore.p12` and without 
`log4j2.trustStoreKeyStoreType`,
   and load a configuration over HTTPS.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to