On HTTPS, REST invocations fail with "SunCertPathBuilderException" error (Doc ID 2145775.1)

Last updated on MARCH 19, 2017

Applies to:

Oracle SOA Suite - Version 12.1.3.0.0 and later
Oracle WebLogic Server - Version 12.1.3.0.0 and later
Information in this document applies to any platform.

Symptoms

When invoking web services over HTTPS, only SOAP requests are successful. REST invocations fail with the "SunCertPathBuilderException" error.

[2016-05-17T14:11:53.791-04:00] [igsoa001]
[ERROR] [] [oracle.soa.bpel.engine.ws] [tid: [ACTIVE].ExecuteThread: '2' for queue: 'weblogic.kernel.Default (self-tuning)'] [userId: ] [ecid: a6690703-8d57-40af-8cf1-ce81147939c4-00003d31,1:19013] [APP: soa-infra] [oracle.soa.tracking.FlowId: 1270529] [oracle.soa.tracking.InstanceId:
5133395] [oracle.soa.tracking.SCAEntityId: 240112] [oracle.soa.tracking.FaultId: 1630316] [composite_name: ProcessIDMSyncPackage!2.0] [FlowId: 0000LIzug2e4epkioxIbKI1NCKE^00005^]
got FabricInvocationException,
Cikey=5133395,
FlowId=1270529,
Current Activity Key=5133395-BpInv0-BpSeq0.3-2, Current Activity
Label=InvokeOnstarAPI,
InvokeMessageGuid=d5877f60-1c5a-11e6-b3f9-005056813293,
ComponentDN=default/ProcessIDMSyncPackage!2.0*soa_a332bc24-dfa2-484c-8e19-857e6ecb11ec/ProcessSyncIDM_WS[[sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
at sun.security.provider.certpath.SunCertPathBuilder.engineBuild(SunCertPathBuilder.java:196)
        at java.security.cert.CertPathBuilder.build(CertPathBuilder.java:268)
        at sun.security.validator.PKIXValidator.doBuild(PKIXValidator.java:380)
        at sun.security.validator.PKIXValidator.engineValidate(PKIXValidator.java:292)
        at sun.security.validator.Validator.validate(Validator.java:260)
        at sun.security.ssl.X509TrustManagerImpl.validate(X509TrustManagerImpl.java:326)
        at sun.security.ssl.X509TrustManagerImpl.checkTrusted(X509TrustManagerImpl.java:231)
        at sun.security.ssl.X509TrustManagerImpl.checkServerTrusted(X509TrustManagerImpl.java:126)
        at sun.security.ssl.ClientHandshaker.serverCertificate(ClientHandshaker.java:1428)
        at sun.security.ssl.ClientHandshaker.processMessage(ClientHandshaker.java:209)
        at sun.security.ssl.Handshaker.processLoop(Handshaker.java:901)
        at sun.security.ssl.Handshaker.process_record(Handshaker.java:837)
        [...]

 

Changes

 In WLS console, there was the following SSL setup:

- host verification set to None
- identity/trust stores: custom identity / custom trust

These parameters were already added in setDomainEnv.sh:

-Dweblogic.security.SSL.ignoreHostnameVerification=true
-Dweblogic.security.SSL.enforceConstraints
-Dweblogic.security.SSL.trustedCAKeyStore
-Dweblogic.security.SSL.nojce
-Djavax.net.ssl.trustStore

Cause

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms