Meanwhile I found out, that key in keystore was saved in PKCS8 format, not PKCS12 as expected. So I recreated the keystore with OpenSSL (means export key and certs, remove passphrase from exported key, create new keystore in P12-format) and afterwords it worked smoothly. Cheers Rene