apache / apache/cloudstack

The documented RabbitMQ credential encryption feature using Jasypt is non-functional on CloudStack 4.22.x

オープン
#13,352 コメント 3 件 リアクション 0 件 担当者 0 名 @DaanHoogland が担当を希望しています GitHub で見る
component:management-server type:bug
主要言語
Java
スター
3.1k
フォーク
1.4k
平均マージ
6日 19時間
マージ済み PR(30日)
32

説明

### problem

If we follow the documented RabbitMQ credential encryption feature, literally copy paste the configuration from https://docs.cloudstack.apache.org/en/4.22.0.0/adminguide/events.html , the encrypted credentials are not being decrypted and RabbitMQ connection is not established. Instead the error messages are thrown to the management server log about missing classes.

Upon further analysis it seems the jasypt library is incompatible with Spring 5+. There is a https://github.com/jasypt/jasypt/issues/25 and/or https://github.com/jasypt/jasypt/issues/35 . And so this is most probably the root cause as the class fails to load on Spring 5 which CloudStack is using.

### versions

CloudStack 4.22.1.0 and also 4.22.0.1, Standard management server install, Ubuntu

### The steps to reproduce the bug

STEPS TO REPRODUCE
1. Follow the AMQP configuration documentation at https://docs.cloudstack.apache.org/en/4.22.0.0/adminguide/events.html
2. Add the documented Jasypt bean configuration to spring-event-bus-context.xml
3. Restart cloudstack-management

EXPECTED BEHAVIOUR:
Encrypted credentials are decrypted and RabbitMQ connection is established.

ACTUAL BEHAVIOUR:
```
Error creating bean with name 'org.apache.cloudstack.spring.lifecycle.ConfigDepotLifeCycle#0': Unsatisfied dependency expressed through field 'configDepotAdmin'; nested exception is org.springframework.beans.factory.CannotLoadBeanClassException: Cannot find class [org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer] for bean with name 'propertyConfigurer' defined in file [/etc/cloudstack/management/META-INF/cloudstack/event/spring-event-bus-context.xml]; nested exception is java.lang.ClassNotFoundException: org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer
/var/log/cloudstack/management/management-server.log.2026-06-03.gz:Caused by: org.springframework.beans.factory.CannotLoadBeanClassException: Cannot find class [org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer] for bean with name 'propertyConfigurer' defined in file [/etc/cloudstack/management/META-INF/cloudstack/event/spring-event-bus-context.xml]; nested exception is java.lang.ClassNotFoundException: org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer
/var/log/cloudstack/management/management-server.log.2026-06-03.gz:Caused by: java.lang.ClassNotFoundException: org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer
```

### What to do about it?

Replace the implementation with a Spring 5-compatible alternative
and/or document a supported workaround. Also, there is second issue with the PBEWithMD5AndDES is no longer considered secure, so the solution shall be future proof.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

まず、オープンな pull request #13676 と events.html に記載されている AMQP 設定を確認します。spring-event-bus-context.xml と management-server.log の例外を調査し、欠落している Jasypt クラスを追跡します。文書化された暗号化済み RabbitMQ 認証情報が Spring 5 互換の設定で機能し、安全な代替手段またはサポート対象の回避策が文書化されていれば完了です。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
java, rabbitmq, spring
領域
backend, security
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
35/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。