Module Signer self-signing failures fall into three separate branches: Java cannot launch the signer, the signer cannot unlock the private key, or the certificate-chain file does not match the selected key pair. Test those branches in order. A keystore is the protected container holding the key pair; an alias selects one entry in that container; a certificate chain is the PKCS #7 file supplied alongside the private key.
Failure-branch identification
| Observed result | Meaning | Next check |
|---|---|---|
JNI error has occurred. Check your installation error |
Java failed while launching or loading the signer. The certificate and module arguments may not have been processed. | Check 1: Java launch path |
keystore was tampered with or password is incorrect |
The signer could not open the selected keystore using the supplied value. A mistyped password or command argument can produce this result. | Check 2: keystore access |
no RSA PrivateKey found for alias 'gcm_certificate' |
The selected alias does not resolve to an RSA private-key entry in the opened keystore. | Check 3: alias and key-pair entry |
No .p7b file is available |
Creating a key pair did not automatically create the separate chain file required by the command. | Check 4: chain export |
| The signer runs but does not produce the intended output | One or more paths, quoted values, or input/output selections are wrong. | Check 5: complete command review |
Check 1: Java launch path
Run java -version from the same PowerShell session that will run Module Signer. Expect Java to start and print its runtime information. If PowerShell cannot find Java, or Java itself fails, repair the Java installation or command search path before examining certificates.
Next, invoke the signer JAR without treating its signing arguments as the first diagnostic target:
java -jar module-signer.jar
Expect the Java process to load the JAR and reach the signer's own command handling. A JNI startup error remains a Java/JAR launch problem. It is not evidence that the .p7b chain or keystore password is wrong, because those values are meaningful only after the application starts processing arguments.
Confirm that module-signer.jar resolves to the intended file. In PowerShell, use an explicit path when the JAR is not in the current directory. If multiple Java installations exist, run the same Java executable for both checks and read its displayed runtime information rather than assuming which installation PowerShell selected.
Check 2: Keystore access
Open the keystore in KeyStore Explorer using the intended keystore password. Expect the file to open and display the generated key-pair entry. Failure here identifies the keystore file or password before Module Signer enters the test.
Then compare the exact PowerShell values passed to -keystore and -keystore-pwd. The demonstrated keystore was tampered with or password is incorrect failure was caused by a typo. Treat spelling, path selection, and quoting as measurable inputs:
- Copy the keystore path from the actual file location. Expect it to identify the same keystore opened in KeyStore Explorer.
- Retype the keystore password deliberately. Expect it to unlock that file without substitution or omitted characters.
- Place quotes around parameter values in PowerShell, particularly paths or values containing shell-sensitive characters. Expect each option to arrive as one argument.
- Check that
-alias-pwdcontains the password protecting the key entry, while-keystore-pwdcontains the password opening the keystore. Expect each credential to work at its respective layer.
Do not regenerate certificates merely because this message appears. First remove transcription errors and prove that the selected container opens.
Check 3: RSA private-key alias
An alias is not the private key itself; it is the name used to locate an entry. Module Signer requires the selected entry to contain an RSA private key. A certificate-only entry, a misspelled alias, or an alias from another keystore cannot satisfy that lookup.
- In KeyStore Explorer, inspect the entry created by Generate New Key Pair. Expect it to be a key-pair entry rather than an imported certificate without its private key.
- Read the alias exactly as displayed. Expect the value supplied to
-aliasto match it character for character. - Inspect the key algorithm for that entry. Expect RSA. If the entry uses another algorithm, generate the required RSA key pair instead of renaming the entry.
- Confirm that the selected keystore contains that alias. Expect the alias lookup and private-key lookup to succeed in the same file.
For the reported message no RSA PrivateKey found for alias 'gcm_certificate', examine gcm_certificate in the opened keystore. The deciding observation is whether that exact entry contains an RSA private key.
Check 4: PKCS #7 chain export
Key-pair generation and certificate-chain export are separate operations. The -chain argument points to an exported file; it does not point back into the keystore.
- Generate a new key pair in KeyStore Explorer if a suitable RSA key-pair entry does not already exist.
- Right-click the intended key pair and select Export, then Export Certificate Chain.
- Select Entire Chain. Expect the export to contain the full chain associated with that entry.
- Select PKCS #7 as the export format.
- Save the result as a
.p7bfile and record its path. Expect that exact file to be used by-chain.
Export the chain from the same entry named by -alias. A chain exported from a different key pair may be syntactically valid while failing to represent the signing key selected from the keystore.
Resolving command construction
Build the command only after the preceding checks pass. In PowerShell, quote the supplied values so paths and aliases remain single arguments:
java -jar module-signer.jar `
-keystore="/keystore.jks" `
-keystore-pwd="<keystore-password>" `
-alias="<key-pair-alias>" `
-alias-pwd="<alias-password>" `
-chain="/cert.p7b" `
-module-in="/my-unsigned-module.modl" `
-module-out="/my-signed-module.modl"
Replace every placeholder and example path with the actual value. Keep the input and output paths distinct so the unsigned source remains available for comparison. Check that -module-in points to the existing unsigned module and that the parent location for -module-out is writable.
Read the command left to right before execution. Expect one keystore, its correct opening password, one RSA private-key alias, that entry's password, the matching exported .p7b chain, an existing input module, and a distinct output module.
Numbered verification readings
-
Check 1: Run
java -version. Expect Java runtime information without a JNI startup failure. -
Check 2: Open the selected
.jksfile in KeyStore Explorer. Expect the keystore password to work and the intended key-pair entry to appear. - Check 3: Inspect the selected alias. Expect an RSA private key, not only a certificate.
-
Check 4: Inspect the
-chainpath. Expect an existing.p7bexported as PKCS #7 with Entire Chain selected from that same key pair. -
Check 5: Run the completed command. Expect no keystore-password or missing-RSA-private-key error and expect the file named by
-module-outto be created.
FAQ
How do I create the p7b file for Module Signer?
In KeyStore Explorer, right-click the key pair, select Export and Export Certificate Chain, choose Entire Chain, and export in PKCS #7 format as a .p7b file.
How do I fix the Module Signer JNI error?
Run java -version, then test java -jar module-signer.jar. If the JNI error occurs before the signer handles arguments, correct the Java/JAR launch path before changing the keystore or chain.
How do I fix a keystore password incorrect error?
Open the same keystore in KeyStore Explorer, verify its password, and compare the exact -keystore and -keystore-pwd values. Check for typos and quote PowerShell argument values.
How do I fix no RSA PrivateKey found for an alias?
Confirm that -alias exactly names a key-pair entry in the selected keystore and that its private-key algorithm is RSA. A certificate-only entry cannot provide the required private key.
How do I verify that Module Signer completed successfully?
Check the path supplied to -module-out. Expect the signed .modl file to exist there after the command exits without the JNI, keystore-password, or RSA-private-key errors.