SAP Knowledge Base Article - Preview

3574634 - OAuth2 authentication in Cloud Integration fails with PKIX path building error

Symptom

When an integration flow in SAP Cloud Integration uses an OAuth2-based security material for outbound communication, the message processing fails with the following error:


sun.security.validator.ValidatorException: PKIX path building failed: 
sun.security.provider.certpath.SunCertPathBuilderException: 
unable to find valid certification path to requested target

This error occurs regardless of which OAuth2 grant type is configured in the security material:

  • OAuth2 Client Credentials
  • OAuth2 SAML Bearer Assertion
  • OAuth2 Authorization Code

The error appears even when the target endpoint itself is reachable and the TLS handshake to the target API server succeeds.


Read more...

Environment

  • SAP Integration Suite 
  • SAP Business Technology Platform 
  • Cloud Integration

Product

Cloud Integration all versions ; SAP Integration Suite all versions

Keywords

OAuth2 Client Credentials, OAuth2 SAML Bearer Assertion, OAuth2 Authorization Code, PKIX path building failed, unable to find valid certification path, SunCertPathBuilderException, Token Service URL, outbound TLS, security material, keystore, root certificate, Cloud Integration, SAP Integration Suite, cpi, , KBA , LOD-HCI-PI-CON-SOAP , SOAP Adapter , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.