My Oracle Support Banner

On HTTPS, REST invocations fail with "SunCertPathBuilderException" error (Doc ID 2145775.1)

Last updated on DECEMBER 11, 2017

Applies to:

Oracle SOA Suite - Version 12.1.3.0.0 and later
Oracle WebLogic Server - Version 12.1.3.0.0 and later
Information in this document applies to any platform.

Symptoms

When invoking web services over HTTPS, only SOAP requests are successful. REST invocations fail with the "SunCertPathBuilderException" error.

[2016-05-17T14:11:53.791-04:00] [igsoa001]
[ERROR] [] [oracle.soa.bpel.engine.ws] [tid: [ACTIVE].ExecuteThread: '2' for queue: 'weblogic.kernel.Default (self-tuning)'] [userId: ] [ecid: a6690703-8d57-40af-8cf1-ce81147939c4-00003d31,1:19013] [APP: soa-infra] [oracle.soa.tracking.FlowId: 1270529] [oracle.soa.tracking.InstanceId:
5133395] [oracle.soa.tracking.SCAEntityId: 240112] [oracle.soa.tracking.FaultId: 1630316] [composite_name: ProcessIDMSyncPackage!2.0] [FlowId: 0000LIzug2e4epkioxIbKI1NCKE^00005^]
got FabricInvocationException,
Cikey=5133395,
FlowId=1270529,
Current Activity Key=5133395-BpInv0-BpSeq0.3-2, Current Activity
Label=InvokeOnstarAPI,
InvokeMessageGuid=d5877f60-1c5a-11e6-b3f9-005056813293,
ComponentDN=default/ProcessIDMSyncPackage!2.0*soa_a332bc24-dfa2-484c-8e19-857e6ecb11ec/ProcessSyncIDM_WS[[sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
at sun.security.provider.certpath.SunCertPathBuilder.engineBuild(SunCertPathBuilder.java:196)
        at java.security.cert.CertPathBuilder.build(CertPathBuilder.java:268)
        at sun.security.validator.PKIXValidator.doBuild(PKIXValidator.java:380)
        at sun.security.validator.PKIXValidator.engineValidate(PKIXValidator.java:292)
        at sun.security.validator.Validator.validate(Validator.java:260)
        at sun.security.ssl.X509TrustManagerImpl.validate(X509TrustManagerImpl.java:326)
        at sun.security.ssl.X509TrustManagerImpl.checkTrusted(X509TrustManagerImpl.java:231)
        at sun.security.ssl.X509TrustManagerImpl.checkServerTrusted(X509TrustManagerImpl.java:126)
        at sun.security.ssl.ClientHandshaker.serverCertificate(ClientHandshaker.java:1428)
        at sun.security.ssl.ClientHandshaker.processMessage(ClientHandshaker.java:209)
        at sun.security.ssl.Handshaker.processLoop(Handshaker.java:901)
        at sun.security.ssl.Handshaker.process_record(Handshaker.java:837)
        [...]

 

Changes

 In WLS console, there was the following SSL setup:

- host verification set to None
- identity/trust stores: custom identity / custom trust

These parameters were already added in setDomainEnv.sh:

-Dweblogic.security.SSL.ignoreHostnameVerification=true
-Dweblogic.security.SSL.enforceConstraints
-Dweblogic.security.SSL.trustedCAKeyStore
-Dweblogic.security.SSL.nojce
-Djavax.net.ssl.trustStore

Cause

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Symptoms
Changes
Cause
Solution
References


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.