<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <div class="moz-cite-prefix">On 7/29/2013 7:16 PM, David Bantz
      wrote:<br>
    </div>
    <blockquote
      cite="mid:68074014-A087-44EA-A706-2A7091804436@Alaska.edu"
      type="cite">
      <div>
        <div><font face="Andale Mono">Caused by:
            javax.net.ssl.SSLHandshakeException:
            sun.security.validator.ValidatorException: PKIX path
            building failed:
            sun.security.provider.certpath.SunCertPathBuilderException:
            unable to find valid certification path to requested target</font></div>
      </div>
      <div><font face="Andale Mono">&#8230;</font></div>
      <br>
      <div><i>What are the possible sources of this failure other than
          having been provided the wrong certificate for the server? &nbsp;
          Do I ALSO need to import the issuing CA certificate? &nbsp;Use a
          different certificate file format?&nbsp;&#8230;</i></div>
    </blockquote>
    <br>
    If there are intermediate certificates in the chain that the server
    is using, and their server is not configured to send the
    intermediate certs during SSL negotiation, and you're only trusting
    the root CA, then this can happen.<br>
    <br>
    You can work around it by adding the intermediate(s) to your cert
    store, but the proper fix is for the server folks to configure SSL
    to send the chain (assuming this is the problem).<br>
    <br>
    <pre class="moz-signature" cols="72">-- 
%%  Christopher A. Bongaarts   %%  <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu">cab@umn.edu</a>          %%
%%  OIT - Identity Management  %%  <a class="moz-txt-link-freetext" href="http://umn.edu/~cab">http://umn.edu/~cab</a>  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%
</pre>
  </body>
</html>