My Oracle Support Banner

E-SSL: While Importing SSL Certificate Using "pskeymanager" Running into Error "keytool error: Get Key Failed: Given final block not properly padded. Such issues can arise if a bad key is used during decryption" (Doc ID 2878116.1)

Last updated on APRIL 23, 2024

Applies to:

PeopleSoft Enterprise PT PeopleTools - Version 8.59 and later
Information in this document applies to any platform.


With 8.59 PeopleTools, when attempting to import signed SSL certificate using pskeymanager, using the following steps:

  1. Navigate to PS_CFG_HOME/webserv/<DOMIAN>/piabin and invoke pskeymanager.
  2. When doing this for the firs time, it will prompt for changing the password of the keystore. Change it.
  3. Create a CSR using the command "pskeymanager –create" command. The last question of this prompt is Private Key Password. Enter any password of your choice.
  4. Submit the CSR to certificate signing authority to get it signed.
  5. Try to import the signed certificate into pskey keystore file using the same pskeymanager utility and it will prompt for Private key password that you provided earlier. 

This certificate import will fail with the following error shown on the screen:

All the instructions about SSL certificate are provided in detail in the following Knowledge Document:

E-SSL: How to Install/Renew an SSL Certificate on WebLogic for PeopleTools 8.51 - 8.59 (Doc ID 1555672.1)



To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!

In this Document

My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.