My Oracle Support Banner

Cannot View The Oamkeystore Keystore On Newer Jdk, Updating Keystore Aliases (Doc ID 2426746.1)

Last updated on JULY 24, 2018

Applies to:

Oracle Access Manager - Version 11.1.2.3.0 and later
Information in this document applies to any platform.

Goal

You are trying to list the aliases in the oamkeystore as you need to add a cert to it, but you have to use an older jdk to view it, otherwise you will get this error:

Jul 19, 2018 10:20:05 AM java.io.ObjectInputStream filterCheck
INFO: ObjectInputFilter REJECTED: class com.sun.crypto.provider.SealedObjectForKeyProtector, array length: -1, nRefs: 1, depth: 1, bytes: 70, ex: n/a
keytool error: java.io.IOException: Invalid secret key format
java.io.IOException: Invalid secret key format
  at com.sun.crypto.provider.JceKeyStore.engineLoad(JceKeyStore.java:861)
  at java.security.KeyStore.load(KeyStore.java:1357)
  at sun.security.tools.KeyTool.doCommands(KeyTool.java:829)
  at sun.security.tools.KeyTool.run(KeyTool.java:363)
  at sun.security.tools.KeyTool.main(KeyTool.java:356)

You cannot view the aliases on the .oamkeystore file. Is there some way to update the .oamkeystore file so that you can view it with current versions of JDK?

You cannot view this keystore using JDK 1.7.0_181, however, can view it using JDK 1.7.0_171. Is there a way to get this keystore to be viewable on the newer JDK?




Solution

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.