apache / apache/cloudstack

The documented RabbitMQ credential encryption feature using Jasypt is non-functional on CloudStack 4.22.x

Aperta
#13,352 3 commenti 0 reazioni 0 assegnatari Rivendicata da @DaanHoogland Vedi su GitHub
component:management-server type:bug
Lingua principale
Java
Stelle
3.1k
Fork
1.4k
Merge medio
6g 19h
PR unite (30g)
32

Descrizione

### problem

If we follow the documented RabbitMQ credential encryption feature, literally copy paste the configuration from https://docs.cloudstack.apache.org/en/4.22.0.0/adminguide/events.html , the encrypted credentials are not being decrypted and RabbitMQ connection is not established. Instead the error messages are thrown to the management server log about missing classes.

Upon further analysis it seems the jasypt library is incompatible with Spring 5+. There is a https://github.com/jasypt/jasypt/issues/25 and/or https://github.com/jasypt/jasypt/issues/35 . And so this is most probably the root cause as the class fails to load on Spring 5 which CloudStack is using.

### versions

CloudStack 4.22.1.0 and also 4.22.0.1, Standard management server install, Ubuntu

### The steps to reproduce the bug

STEPS TO REPRODUCE
1. Follow the AMQP configuration documentation at https://docs.cloudstack.apache.org/en/4.22.0.0/adminguide/events.html
2. Add the documented Jasypt bean configuration to spring-event-bus-context.xml
3. Restart cloudstack-management

EXPECTED BEHAVIOUR:
Encrypted credentials are decrypted and RabbitMQ connection is established.

ACTUAL BEHAVIOUR:
```
Error creating bean with name 'org.apache.cloudstack.spring.lifecycle.ConfigDepotLifeCycle#0': Unsatisfied dependency expressed through field 'configDepotAdmin'; nested exception is org.springframework.beans.factory.CannotLoadBeanClassException: Cannot find class [org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer] for bean with name 'propertyConfigurer' defined in file [/etc/cloudstack/management/META-INF/cloudstack/event/spring-event-bus-context.xml]; nested exception is java.lang.ClassNotFoundException: org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer
/var/log/cloudstack/management/management-server.log.2026-06-03.gz:Caused by: org.springframework.beans.factory.CannotLoadBeanClassException: Cannot find class [org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer] for bean with name 'propertyConfigurer' defined in file [/etc/cloudstack/management/META-INF/cloudstack/event/spring-event-bus-context.xml]; nested exception is java.lang.ClassNotFoundException: org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer
/var/log/cloudstack/management/management-server.log.2026-06-03.gz:Caused by: java.lang.ClassNotFoundException: org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer
```

### What to do about it?

Replace the implementation with a Spring 5-compatible alternative
and/or document a supported workaround. Also, there is second issue with the PBEWithMD5AndDES is no longer considered secure, so the solution shall be future proof.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Inizia esaminando la pull request aperta #13676 e la configurazione AMQP documentata in events.html. Ispeziona spring-event-bus-context.xml e l'eccezione in management-server.log per tracciare la classe Jasypt mancante. Il lavoro è completato quando le credenziali RabbitMQ crittografate documentate funzionano con una configurazione compatibile con Spring 5 e viene documentata una sostituzione sicura o una soluzione alternativa supportata.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
java, rabbitmq, spring
Ambito
backend, security
Tipo di issue
Bug
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Ferma
Chiarezza
Abbastanza chiara
Idoneità per principianti
35/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.