PKIX refers to ‘Public Key Infrastructure (X.509)’ and errors referring to PKIX may be experienced in various java-based ZMF interfaces when attempting secure (i.e. SSL/AT-TLS) connection between entities/applications.
For example, the following message may be reported when attempting a ZMF4ECL connection to a ZMF Server that has the ‘Connections Secured via TLS’ option specified:
Connect Error: PKIX patch building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find Valid Certification path to requested target
Or this type of error could be seen in the ZMFREST output file of a tomcat task when attempting to create a secure dialog with a Jenkins server:
javax.net.ssl.SSLHandshakeException: com.ibm.jsse2.util.j: PKIX path building failed: com.ibm.security.cert.IBMCertPathBuilderException: unable to find valid certification path to requested target
As suggested by the text in the above messages, these PKIX errors indicate that the java environment cannot find the trusted certificate(s) that are required to complete connection of the secure dialog. When finding this type of error diagnosis should focus on the import of and access to the required certificates in the key store/trust store of the entities that are attempting to communicate with each other.
#ChangeManZMF
#SupportTips/KnowledgeDocs

