Legacy Knowledge Base
Published Jun. 30, 2025

Error "The SSL private key cannot be parsed" when deploying to Liferay PaaS

Written By

Jamilly Macedo

How To articles are not official guidelines or officially supported documentation. They are community-contributed content and may not always reflect the latest updates to Liferay DXP. We welcome your feedback to improve How To articles!

While we make every effort to ensure this Knowledge Base is accurate, it may not always reflect the most recent updates or official guidelines.We appreciate your understanding and encourage you to reach out with any feedback or concerns.

Legacy Article

You are viewing an article from our legacy "FastTrack" publication program, made available for informational purposes. Articles in this program were published without a requirement for independent editing or verification and are provided"as is" without guarantee.

Before using any information from this article, independently verify its suitability for your situation and project.
Note: please note that Liferay has renamed its Liferay Experience Could offerings to Liferay SaaS (formerly LXC) and Liferay PaaS (formerly LXC-SM).

Issue

  • When attempting to deploy to Liferay Liferay PaaS, the build fails with the following error message:
Some error has happened during the build. Try again. [{"message":"Bad Request","status":400,"errors":[{"reason":"privateKeyCannotBeParsed","context":{"message":"The SSL private key cannot be parsed"}}]}].

Environment

  • Liferay PaaS

Resolution

  • This error means that the "key" field in the Webserver's LCP.json file contains invalid or incorrect data.
  • Make sure these fields are properly formatted or without encrypted data and deploy again.

  • Common mistakes are:

    • Invalid base64 formatting: you MUST format the whole certificate, starting with (and including) -----BEGIN CERTIFICATE----- until (and including) -----END CERTIFICATE----- (the dashes also matter!);
    • The certificate is not in a supported format: Liferay Cloud only supports RSA-2048 or ECDSA P-256. We do not support RSA-4096.

Additional Information

Did this article resolve your issue ?

Legacy Knowledge Base