Skip to content

The documented RabbitMQ credential encryption feature using Jasypt is non-functional on CloudStack 4.22.x #13352

Description

@durdin85

problem

If we follow the documented RabbitMQ credential encryption feature, literally copy paste the configuration from https://docs.cloudstack.apache.org/en/4.22.0.0/adminguide/events.html , the encrypted credentials are not being decrypted and RabbitMQ connection is not established. Instead the error messages are thrown to the management server log about missing classes.

Upon further analysis it seems the jasypt library is incompatible with Spring 5+. There is a jasypt/jasypt#25 and/or jasypt/jasypt#35 . And so this is most probably the root cause as the class fails to load on Spring 5 which CloudStack is using.

versions

CloudStack 4.22.1.0 and also 4.22.0.1, Standard management server install, Ubuntu

The steps to reproduce the bug

STEPS TO REPRODUCE

  1. Follow the AMQP configuration documentation at https://docs.cloudstack.apache.org/en/4.22.0.0/adminguide/events.html
  2. Add the documented Jasypt bean configuration to spring-event-bus-context.xml
  3. Restart cloudstack-management

EXPECTED BEHAVIOUR:
Encrypted credentials are decrypted and RabbitMQ connection is established.

ACTUAL BEHAVIOUR:

Error creating bean with name 'org.apache.cloudstack.spring.lifecycle.ConfigDepotLifeCycle#0': Unsatisfied dependency expressed through field 'configDepotAdmin'; nested exception is org.springframework.beans.factory.CannotLoadBeanClassException: Cannot find class [org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer] for bean with name 'propertyConfigurer' defined in file [/etc/cloudstack/management/META-INF/cloudstack/event/spring-event-bus-context.xml]; nested exception is java.lang.ClassNotFoundException: org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer
/var/log/cloudstack/management/management-server.log.2026-06-03.gz:Caused by: org.springframework.beans.factory.CannotLoadBeanClassException: Cannot find class [org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer] for bean with name 'propertyConfigurer' defined in file [/etc/cloudstack/management/META-INF/cloudstack/event/spring-event-bus-context.xml]; nested exception is java.lang.ClassNotFoundException: org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer
/var/log/cloudstack/management/management-server.log.2026-06-03.gz:Caused by: java.lang.ClassNotFoundException: org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer

What to do about it?

Replace the implementation with a Spring 5-compatible alternative
and/or document a supported workaround. Also, there is second issue with the PBEWithMD5AndDES is no longer considered secure, so the solution shall be future proof.

Activity

  1. boring-cyborg commented on Jun 5, 2026

    @boring-cyborg

    Thanks for opening your first issue here! Be sure to follow the issue template!

  2. added this to the 4.24.0 milestone on Jun 15, 2026
  3. DaanHoogland commented on Jul 24, 2026

    @DaanHoogland
    Contributor

    @durdin85 can you have a look if #13676 solves your issue(s)?

  4. github-actions commented on Aug 19, 2026

    @github-actions

    🎯 Triage report

    Following the documented Jasypt-based RabbitMQ credential encryption setup fails with ClassNotFoundException: org.jasypt.spring3.properties.EncryptablePropertyPlaceholderConfigurer. The reporter traced this to Jasypt's spring3 module being incompatible with the Spring 5 version CloudStack uses. A maintainer has since pointed at PR #13676 as a possible fix, pending confirmation from the reporter.

    📊 Assessment

    Dimension Value Reasoning
    Type type:bug Documented, officially supported configuration does not work as documented — a functional defect (and doc/config mismatch).
    Component component:management-server Event bus/RabbitMQ integration is part of the management server.
    Severity n/a Not independently assessed; feature is non-functional but has a workaround (skip encryption) and a candidate fix already in flight.
    Labels type:bug, component:management-server See above
    Coding agent Needs more info A candidate PR (#13676) already exists; work should be verification/finishing that PR rather than a fresh implementation, and requires reporter/maintainer confirmation it resolves the issue.
    💡 Notes and suggestions
    • Related PR: add rabbitmq jasypt property encryption facility #13676 (maintainer-linked, pending confirmation from reporter as of 2026-07-24).
    • The reporter also flagged that even if the class-loading issue is fixed, PBEWithMD5AndDES (the cipher used) is weak and should be replaced with a modern algorithm as part of any fix.
    • No other similar existing issues were found in a quick search.

    Generated by Daily Issue Triage · sonnet50 262K · ◷

    Add this agentic workflows to your repo

    To install this agentic workflow, run

    gh aw add githubnext/agentics/workflows/daily-issue-triage.md@d7c1dc4b72b00607a67caaffdcc216cb64379cf9
    
  5. modified the milestones: 4.24.0, 4.22.2 on Aug 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions