# API call from watcher using webhook, certificate error

**URL:** <https://discuss.elastic.co/t/api-call-from-watcher-using-webhook-certificate-error/270363>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [April 16, 2021, 9:18am UTC](https://discuss.elastic.co/t/api-call-from-watcher-using-webhook-certificate-error/270363 "2021-04-16T09:18:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![avy](https://avatars.discourse-cdn.com/v4/letter/a/9e8a1a/32.png) [@avy](https://discuss.elastic.co/u/avy)\
**Post date:** [April 16, 2021, 9:18am UTC](https://discuss.elastic.co/t/api-call-from-watcher-using-webhook-certificate-error/270363/1 "2021-04-16T09:18:39Z")

</div>

Hi,

We are trying to make API call as part of watcher action, using webhook to 3rd party application.

When we do that we are getting below error:

```auto
"type": "s_s_l_handshake_exception",
              "reason": "PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target"
            }
          ],
          "type": "s_s_l_handshake_exception",
          "reason": "PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target",
          "caused_by": {
            "type": "validator_exception",
            "reason": "PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target",
            "caused_by": {
              "type": "sun_cert_path_builder_exception",
              "reason": "unable to find valid certification path to requested target"

```

* * *

We wanted to understand where exactly we configure the certificate to resolve this issue.

We tried to add this in elasticsearch.yml as below:

```auto
xpack.security.enabled: true
xpack.security.http.ssl.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.http.ssl.key: <Key Path>
xpack.http.ssl.certificate: <Certificate Path>
xpack.http.ssl.certificate_authorities: ["<Certificate Path>"]

```

Thanks  
Avy

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 19, 2021, 11:34pm UTC](https://discuss.elastic.co/t/api-call-from-watcher-using-webhook-certificate-error/270363/2 "2021-04-19T23:34:13Z")

</div>

Welcome to our community! 😃

I am not 100% sure of this, but I would start by trying to add the certificate to the local machine/user store and validating that it works with something like curl.

---

<div class="post-metadata">

**Author:** ![avy](https://avatars.discourse-cdn.com/v4/letter/a/9e8a1a/32.png) [@avy](https://discuss.elastic.co/u/avy)\
**Post date:** [April 20, 2021, 7:44am UTC](https://discuss.elastic.co/t/api-call-from-watcher-using-webhook-certificate-error/270363/3 "2021-04-20T07:44:20Z")

</div>

Thanks for the reply.

We already tried that and its not working.

We installed it on windows server on which elastic is running, we installed it in Java keystore as well.

Still issue is not resolved.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2021, 7:44am UTC](https://discuss.elastic.co/t/api-call-from-watcher-using-webhook-certificate-error/270363/4 "2021-05-18T07:44:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
