javax.net.ssl.SSLHandshakeException: PKIX path building failed: unable to find valid certification path to requested target
Java doesn’t trust the server’s certificate chain (self-signed, corporate proxy CA, or missing intermediate).
Seen on:
Java
Meaning
The JVM uses its own truststore (cacerts), not the OS one. Corporate SSL inspection and internal CAs must be imported into the JDK’s truststore.
Common causes
- Self-signed/internal CA certificate
- Corporate proxy re-signing HTTPS
- Server missing intermediate certificates
- Old JDK without newer root CAs
⚡ Quick fix
- Import the CA into the JDK truststore with keytool
- Fix the server chain
- Update the JDK
Detailed fix by platform
Java
keytool -importcert -alias corp-root -file corp-root.pem -keystore "$JAVA_HOME/lib/security/cacerts" -storepass changeit
How to diagnose
- Chain — openssl s_client output
- Truststore — Which JDK/cacerts is used?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026