'javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path' error when testing a RESTful Web Service AFX Connector in RSA Identity Governance & Lifecycle
Originally Published: 2020-04-10
Article Number
Applies To
RSA Version/Condition: 7.0.x, 7.1.x, 7.2.x
Issue
javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path.
- Connector in a Running state:
- Output from a test of the connector:
- Accessing the same URL via a REST/SOAP tool has no issues:
Cause
Resolution
- Launch Firefox.
- Open the URL being accessed by the AFX RESTful web service connector.
- In the left-hand corner, click on the lock icon or the Info button to see the certificate issuer.
- Click the > at the right for more details.
- Click the More Information button.
- Click View Certificate.
- Scroll down until you see the Download option:
PEM (cert) PEM (chain)
- Click on PEM (cert) to download the certificate in PEM format.
- Import the certificate to the JVM cacert as the root user:
keytool -importcert -alias startssl -keystore $JAVA_HOME/jre/lib/security/cacerts -storepass changeit -file <path to the cert saved in step 7a>
- After importing the certificate, restart the AFX server as the afx user:
afx stop afx start
Related Articles
RSA enVision Software Supported Upgrade Paths 35Number of Views Collector or AFX Connector or JSP or Collector or Connector TEST fails with "PKIX path building failed" in RSA Governance … 425Number of Views RSA Identity Governance & Lifecycle Access Fulfillment Express (AFX) failure java.lang.NoClassDefFoundError: sun/net/www/p… 84Number of Views RSA Identity Governance and Lifecycle RESTful web service response: java.lang.IllegalStateException 281Number of Views AFX test connector settings button times out and the test connector capabilities work or the test connector capabilities f… 391Number of Views
Trending Articles
Troubleshooting Web Tier deployments on Red Hat Enterprise Linux for RSA Authentication Manager 8.1 RSA-2026-07: RSA Identity Router Security Update for Third-Party Component Vulnerabilities How to Replace the Web Server Certificate for the RSA Identity Governance & Lifecycle Web Console Installing rsaservmgr scripts [exec] error reading information on service rsaservmgr error when installing RSA Web Tier o… RSA-2026-05: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities
Don't see what you're looking for?