The documented RabbitMQ credential encryption feature using Jasypt is non-functional on CloudStack 4.22.x
- Dominant language
- Java
- Stars
- 3.1k
- Forks
- 1.4k
- Avg merge
- 6d 19h
- Merged PRs (30d)
- 32
Description
### problem
If we follow the documented RabbitMQ credential encryption feature, literally copy paste the configuration from https://docs.cloudstack.apache.org/en/4.22.0.0/adminguide/events.html , the encrypted credentials are not being decrypted and RabbitMQ connection is not established. Instead the error messages are thrown to the management server log about missing classes.
Upon further analysis it seems the jasypt library is incompatible with Spring 5+. There is a https://github.com/jasypt/jasypt/issues/25 and/or https://github.com/jasypt/jasypt/issues/35 . And so this is most probably the root cause as the class fails to load on Spring 5 which CloudStack is using.
### versions
CloudStack 4.22.1.0 and also 4.22.0.1, Standard management server install, Ubuntu
### The steps to reproduce the bug
STEPS TO REPRODUCE
1. Follow the AMQP configuration documentation at https://docs.cloudstack.apache.org/en/4.22.0.0/adminguide/events.html
2. Add the documented Jasypt bean configuration to spring-event-bus-context.xml
3. Restart cloudstack-management
EXPECTED BEHAVIOUR:
Encrypted credentials are decrypted and RabbitMQ connection is established.
ACTUAL BEHAVIOUR:
```
Error creating bean with name 'org.apache.cloudstack.spring.lifecycle.ConfigDepotLifeCycle#0': Unsatisfied dependency expressed through field 'configDepotAdmin'; nested exception is org.springframework.beans.factory.CannotLoadBeanClassException: Cannot find class [org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer] for bean with name 'propertyConfigurer' defined in file [/etc/cloudstack/management/META-INF/cloudstack/event/spring-event-bus-context.xml]; nested exception is java.lang.ClassNotFoundException: org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer
/var/log/cloudstack/management/management-server.log.2026-06-03.gz:Caused by: org.springframework.beans.factory.CannotLoadBeanClassException: Cannot find class [org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer] for bean with name 'propertyConfigurer' defined in file [/etc/cloudstack/management/META-INF/cloudstack/event/spring-event-bus-context.xml]; nested exception is java.lang.ClassNotFoundException: org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer
/var/log/cloudstack/management/management-server.log.2026-06-03.gz:Caused by: java.lang.ClassNotFoundException: org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer
```
### What to do about it?
Replace the implementation with a Spring 5-compatible alternative
and/or document a supported workaround. Also, there is second issue with the PBEWithMD5AndDES is no longer considered secure, so the solution shall be future proof.
Contributor guide
Research direction
Start by reviewing open pull request #13676 and the documented AMQP configuration in events.html. Inspect spring-event-bus-context.xml and the management-server.log exception to trace the missing Jasypt class. Done means the documented encrypted RabbitMQ credentials work with Spring 5-compatible configuration and a secure replacement or supported workaround is documented.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, rabbitmq, spring
- Domain
- backend, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100