I have a java code with HTTPURL connection it keep saying the error as below and it states error in 47th line.
javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target|
It also shows error in line 47: OutputStream output = httpURLConnection.getOutputStream();
couldn't trace url responsecode, thou url is active to access.
here is the stack trace and javacode
https://gist.github.com/theakathir/c9138e3ea7470b698ec06a7db7dcdeab
Appreciate if someone could assist on this to resolve. Thanks
The server's domain certificate is usually signed by an intermediate certificate authority which in turn is signed by the root certificate authority. All common clients (browsers- chrome, mozilla, internet-explorer, safari, opera and the java-vm) have their own trust-store with the certificate authority already bundled during installation.
The exceptions means that you are pointing to a server whose server certificate has not been signed by a certificate authority trusted by the jvm.
In such cases you usually build your own trust-manager instead of modifying the jvm's default truststore (located at $JAVA_HOME\jre\lib\security\cacerts).
Code snippet would look something like this :
package com.example.so.tls;
import java.io.File;
import java.io.FileInputStream;
import java.io.FileNotFoundException;
import java.io.IOException;
import java.net.URL;
import java.security.KeyManagementException;
import java.security.KeyStore;
import java.security.KeyStoreException;
import java.security.NoSuchAlgorithmException;
import java.security.cert.CertificateException;
import javax.net.ssl.HttpsURLConnection;
import javax.net.ssl.SSLContext;
import javax.net.ssl.SSLSocketFactory;
import javax.net.ssl.TrustManagerFactory;
/**
* <p> https://stackoverflow.com/q/44607949/2862341 </p>
* @author ravindra
*/
public class TestCustomTruststore {
public static void main(String[] args) {
String pathToTruststore = "/path/to/customTruststore.jks"; // truststore has the server certificate loaded
try {
File file = new File(pathToTruststore);
KeyStore trustStore = KeyStore.getInstance("jks");
trustStore.load(new FileInputStream(file), null);
TrustManagerFactory trustManagerFactory = TrustManagerFactory.getInstance("PKIX");
trustManagerFactory.init(trustStore);
SSLContext sslContext = SSLContext.getInstance("TLS");
sslContext.init(null, trustManagerFactory.getTrustManagers(), null);
SSLSocketFactory sslSocketFactory = sslContext.getSocketFactory();
String urlStr = "https://example.com";
URL url = new URL(urlStr);
HttpsURLConnection httpsURLConnection = (HttpsURLConnection) url.openConnection();
httpsURLConnection.setSSLSocketFactory(sslSocketFactory);
httpsURLConnection.getInputStream();
} catch (KeyStoreException e) {
e.printStackTrace();
} catch (NoSuchAlgorithmException e) {
e.printStackTrace();
} catch (CertificateException e) {
e.printStackTrace();
} catch (FileNotFoundException e) {
e.printStackTrace();
} catch (IOException e) {
e.printStackTrace();
} catch (KeyManagementException e) {
e.printStackTrace();
}
}
}
PS: You'd need to use $JAVA_HOME\bin\keytool utility to create the keystore and load the certificate.
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With