I am not 100% certain but I believe the sun.security.pkcs12.PKCS12KeyStore.engineLoad &/or java.security.KeyStore.load modules within confluence are not accounting for or stripping whitespace from the password specified for loading pkcs12 certificate chains.
I can verify the pkcs12 using both openssl & the bundled keytool without error. Steps taken below follow:
Using keytool:
%> jre/bin/keytool -list -keystore certificate.pkcs12 -storetype PKCS12
Enter keystore password:
Keystore type: PKCS12
Keystore provider: SunJSSE
Your keystore contains 1 entry
1, Oct 8, 2014, PrivateKeyEntry,
Certificate fingerprint (SHA1): 5A:8A:B0:26:E1:39:C1:0E:52:F5:0C:E3:8E:31:74:24:9D:9D:AE:F9
Using OpenSSL:
%> openssl pkcs12 -noout -in certificate.pkcs12
Enter Import Password:
MAC verified OK
Here is the server.xml file (relevant to use of a pkcs12 for ssl access)
<Connector port="8443"
maxHttpHeaderSize="8192" SSLEnabled="true"
maxThreads="150" minSpareThreads="25"
enableLookups="false" disableUploadTimeout="true"
acceptCount="100" scheme="https" secure="true"
clientAuth="false" sslProtocol="TLS" useBodyEncodingForURI="true"
keystoreFile="/full/path/to/certificate.pkcs12"
keystorePass="password with spaces" keystoreType="PKCS12" keyAlias="1" />