PKIX path building failed ☕ Java

javax.net.ssl.SSLHandshakeException: PKIX path building failed: unable to find valid certification path to requested target

Java doesn’t trust the server’s certificate chain (self-signed, corporate proxy CA, or missing intermediate).

Seen on: Java

Meaning

The JVM uses its own truststore (cacerts), not the OS one. Corporate SSL inspection and internal CAs must be imported into the JDK’s truststore.

Common causes

  • Self-signed/internal CA certificate
  • Corporate proxy re-signing HTTPS
  • Server missing intermediate certificates
  • Old JDK without newer root CAs

⚡ Quick fix

  1. Import the CA into the JDK truststore with keytool
  2. Fix the server chain
  3. Update the JDK

Detailed fix by platform

Java

  1. keytool -importcert -alias corp-root -file corp-root.pem -keystore "$JAVA_HOME/lib/security/cacerts" -storepass changeit

How to diagnose

  1. Chain — openssl s_client output
  2. Truststore — Which JDK/cacerts is used?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.