keystore

Version

Configuration element for a keystore holding private keys and certificates.

Syntax

keystore:
keyAlias: <string>
keyPassword: <string>
location: <string>
password: <string>
provider: <string>
type: <string>
keystore:
  keyAlias: <string>
  keyPassword: <string>
  location: <string>
  password: <string>
  provider: <string>
  type: <string>

Attributes

NameRequiredDefaultDescriptionExamples
keyAliasfalse-The alias identifying which key entry to use from the keystore.-
keyPasswordfalsechangeitPassword used to unlock the private key entry in the keystore.abc123
locationfalse-A file/resource containing the PKCS#12 keystore (*.p12).-
passwordfalse-The password used to open the keystore/truststore.-
providerfalse-Provider to use when loading the keystore.-
typefalse-Keystore type (e.g., PKCS12, JKS), or PEM to load location as one or more bare X.509 certificates (.cer/.crt/.pem) instead of a keystore container. PEM only makes sense for a truststore, since a bare certificate carries no private key. location may hold more than one certificate - either PEM blocks or DER certificates concatenated back to back - and every one of them becomes a separate trust anchor; this is how to trust a CA chain (root plus intermediates) when the peer's messages only ever carry its leaf certificate.-

Can be used in