Skip to content

Chain certificate not imported in the truststore #476

Description

@yoannrt

Describe the Bug

Consider

  java_ks { "$cert_alias:$truststore_path":
    certificate  => $cert_path_unique,
    chain        => $chain_path_unique,
    trustcacerts => true,
    password     => $truststore_passwd
  }

According to the documentation, I thought it would upgrade the keystore with the chain but it's not.

Same thing with the certificate params if $cert_path_unique contains the intermediate and the leaf.

Expected Behavior

The keystore should contain the certificate and the intermediate.

Environment

  • Version [5.1.1]
  • Platform [puppet 8 rhel 9]

Am I missing something ?

Activity

jst-cyr commented on Sep 8, 2026

@jst-cyr
Member

Hi @yoannrt ! Thanks for reporting the issue. You mentioned platform 'Puppet 8'. Is this Open Source Puppet or Puppet Core?

I don't think you are missing anything. Looking at the code, it does look like if you don't provide a private key the logic goes into a block where it doesn't respect the chain properly. From what I can tell, this is an issue. Tagging it as a bug.

added theissue type on Sep 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions