ORACLE EBS/ECC CERTIFICATION ERROR: UNABLE TO FIND VALID CERTIFICATION PATH TO REQUESTED TARGET
We have Oracle Enterprise Command Center integrated with Oracle E-Business suite. EBS accepts traffic on https (offloaded at loadbalancer) and recently the SSL certificate got expired. We decided to use self-signed certificate instead of certificate from popular CAs to save few bucks. After changing certificate at EBS load balancer we started receiving below error from ECC:
javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
at sun.security.ssl.Alerts.getSSLException(Alerts.java:192)
at sun.security.ssl.SSLSocketImpl.fatal(SSLSocketImpl.java:1916)
at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:305)
at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:299)
at sun.security.ssl.ClientHandshaker.serverCertificate(ClientHandshaker.java:1577)
at sun.security.ssl.ClientHandshaker.processMessage(ClientHandshaker.java:213)
at sun.security.ssl.Handshaker.processLoop(Handshaker.java:995)
at sun.security.ssl.Handshaker.process_record(Handshaker.java:931)
at sun.security.ssl.SSLSocketImpl.readRecord(SSLSocketImpl.java:1035)
at sun.security.ssl.SSLSocketImpl.performInitialHandshake(SSLSocketImpl.java:1344)
at sun.security.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:1371)
at sun.security.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:1355)
at sun.net.www.protocol.https.HttpsClient.afterConnect(HttpsClient.java:559)
at sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect(AbstractDelegateHttpsURLConnection.java:185)
at sun.net.www.protocol.http.HttpURLConnection.getInputStream(HttpURLConnection.java:1361)
at java.net.HttpURLConnection.getResponseCode(HttpURLConnection.java:468)
at sun.net.www.protocol.https.HttpsURLConnectionImpl.getResponseCode(HttpsURLConnectionImpl.java:347)
at oracle.ecc.client.util.EccClientUtil.processHttpRequest(EccClientUtil.java:240)
at oracle.ecc.client.EccServicesInvoker.invokeDataServicePvt(EccServicesInvoker.java:327)
at oracle.ecc.client.EccServicesInvoker.invokeDataService(EccServicesInvoker.java:86)
at oracle.apps.fnd.ecc.dataload.EccDataLoadCP.runProgram(EccDataLoadCP.java:280)
at oracle.apps.fnd.cp.request.Run.main(Run.java:159)
Caused by: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
at sun.security.validator.PKIXValidator.doBuild(PKIXValidator.java:395)
at sun.security.validator.PKIXValidator.engineValidate(PKIXValidator.java:302)
at sun.security.validator.Validator.validate(Validator.java:260)
at sun.security.ssl.X509TrustManagerImpl.validate(X509TrustManagerImpl.java:326)
at sun.security.ssl.X509TrustManagerImpl.checkTrusted(X509TrustManagerImpl.java:231)
at sun.security.ssl.X509TrustManagerImpl.checkServerTrusted(X509TrustManagerImpl.java:126)
at sun.security.ssl.ClientHandshaker.serverCertificate(ClientHandshaker.java:1559)At first we were not sure where to add new certificate: ECC trust store or EBS trust store or DB wallet. As you are aware, it all depends who acts as client and who acts as server. Client should trust server certificate, so it should be in client’s trust store. Our first choice was ECC. We added EBS certificate (certificate can be downloaded from any browser or openssl) to ECC java cacerts store. Unfortunately, it didn’t resolve our problem.
We consulted our project team they told us that following url is invoked from EBS app tier as part of concurrent program:
https://mycomany.com:443/ecc/ir/data/ap/datasets?
From this we understood that EBS is acting as client for itself which is a java process. So, we added EBS certificate to java cacerts (usually located at $JDK_HOME/jre/lib/security) and restarted process. Concurrent programs completed successfully post this change.
Comments
Post a Comment