My Oracle Support Banner

OAG Throws"java.security.cert.CertificateException: cannot decode CRL" Error With Large CRL At Runtime, And On Deployment Throws An 'Out Of Memory' Error (Doc ID 1951932.1)

Last updated on JANUARY 06, 2017

Applies to:

Oracle API Gateway - Version 11.1.2 and later
Information in this document applies to any platform.

Symptoms

On : 11.1.2 version, Oracle API Gateway

When attempting to use a "Validate certificate against a Certificate Revocation List" filter in a policy on Policy Studio and the file is about 3MB, the Gateway instance reports a "java.security.cert.CertificateException: cannot decode CRL" error.

Processing smaller CRLs works OK.

ERROR
----------------------

java exception:
java.security.cert.CertificateException: cannot decode CRL
  at com.vordel.security.openssl.OSSLCertificateFactorySpi.engineGenerateCRLFromPEM(Native Method)
  at com.vordel.security.openssl.OSSLCertificateFactorySpi.engineGenerateCRL(OSSLCertificateFactorySpi.java:59)
  at java.security.cert.CertificateFactory.generateCRL(CertificateFactory.java:497)
  at com.vordel.circuit.cert.CRLResponderProcessor.startCRLRetrieval(CRLResponderProcessor.java:156)
  at com.vordel.circuit.cert.CRLResponderProcessor.filterAttached(CRLResponderProcessor.java:102)
  at com.vordel.circuit.cert.CRLValidationProcessor.filterAttached(CRLValidationProcessor.java:25)
  at com.vordel.circuit.FilterContainer.configureFilter(FilterContainer.java:42)
  at com.vordel.circuit.Circuit.createContainer(Circuit.java:271)
  at com.vordel.circuit.Circuit.loadFilter(Circuit.java:215)
  at com.vordel.circuit.Circuit.loadFilter(Circuit.java:219)
  at com.vordel.circuit.Circuit.configure(Circuit.java:184)
  at com.vordel.circuit.CircuitCache.getCircuit(CircuitCache.java:61)
  at com.vordel.circuit.CircuitChainFilter.resolveCircuits(CircuitChainFilter.java:68)
  at com.vordel.circuit.CircuitChainProcessor.attach(CircuitChainProcessor.java:25)
  at com.vordel.dwe.http.HTTPPlugin.configureCircuits(HTTPPlugin.java:125)
  at com.vordel.dwe.http.HTTPPlugin.configure(HTTPPlugin.java:79)
  at com.vordel.dwe.NativeModule.configure(NativeModule.java:146)
  at com.vordel.dwe.NativeModule.configure(NativeModule.java:60)
  at com.vordel.precipitate.SolutionPack.loadModules(SolutionPack.java:618)
  at com.vordel.dwe.Service.refresh(Service.java:437)
  at com.vordel.api.configuration.ConfigurationService.updateConfiguration(ConfigurationService.java:85)
  at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
  at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57)
  at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
  at java.lang.reflect.Method.invoke(Method.java:606)
  at com.sun.jersey.spi.container.JavaMethodInvokerFactory$1.invoke(JavaMethodInvokerFactory.java:60)
  at com.sun.jersey.server.impl.model.method.dispatch.AbstractResourceMethodDispatchProvider$TypeOutInvoker._dispatch(AbstractResourceMethodDispatchProvider.java:185)
  at com.sun.jersey.server.impl.model.method.dispatch.ResourceJavaMethodDispatcher.dispatch(ResourceJavaMethodDispatcher.java:75)
  at com.sun.jersey.server.impl.uri.rules.HttpMethodRule.accept(HttpMethodRule.java:288)
  at com.sun.jersey.server.impl.uri.rules.ResourceClassRule.accept(ResourceClassRule.java:108)
  at com.sun.jersey.server.impl.uri.rules.RightHandPathRule.accept(RightHandPathRule.java:147)
  at com.sun.jersey.server.impl.uri.rules.RootResourceClassesRule.accept(RootResourceClassesRule.java:84)
  at com.sun.jersey.server.impl.application.WebApplicationImpl._handleRequest(WebApplicationImpl.java:1469)
  at com.sun.jersey.server.impl.application.WebApplicationImpl._handleRequest(WebApplicationImpl.java:1400)
  at com.sun.jersey.server.impl.application.WebApplicationImpl.handleRequest(WebApplicationImpl.java:1349)
  at com.sun.jersey.server.impl.application.WebApplicationImpl.handleRequest(WebApplicationImpl.java:1339)
  at com.sun.jersey.spi.container.servlet.WebComponent.service(WebComponent.java:416)
  at com.sun.jersey.spi.container.servlet.ServletContainer.service(ServletContainer.java:537)
  at com.sun.jersey.spi.container.servlet.ServletContainer.service(ServletContainer.java:699)
  at javax.servlet.http.HttpServlet.service(HttpServlet.java:853)

Cause

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Symptoms
Cause
Solution
References


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.