# Connecting to S3 Unable to execute HTTP request: PKIX path building failed

**URL:** <https://discuss.elastic.co/t/connecting-to-s3-unable-to-execute-http-request-pkix-path-building-failed/275827>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, snapshot-and-restore\
**Created:** [June 14, 2021, 11:52am UTC](https://discuss.elastic.co/t/connecting-to-s3-unable-to-execute-http-request-pkix-path-building-failed/275827 "2021-06-14T11:52:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vaclav1](https://avatars.discourse-cdn.com/v4/letter/v/c68b51/32.png) [@vaclav1](https://discuss.elastic.co/u/vaclav1)\
**Post date:** [June 14, 2021, 11:52am UTC](https://discuss.elastic.co/t/connecting-to-s3-unable-to-execute-http-request-pkix-path-building-failed/275827/1 "2021-06-14T11:52:26Z")

</div>

Dear team,

I have imported certificate for the S3 custom bucket to the java cacerts.  
But still got a following issue on verifying repository:

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "repository_verification_exception",
        "reason": "[repository_backup_fat_at_202011] path is not accessible on master node"
      }
    ],
    "type": "repository_verification_exception",
    "reason": "[repository_backup_fat_at_202011] path is not accessible on master node",
    "caused_by": {
      "type": "i_o_exception",
      "reason": "Unable to upload object [tests-fj0Fso5-QoKonfCk3kiNnQ/master.dat] using a single upload",
      "caused_by": {
        "type": "sdk_client_exception",
        "reason": "sdk_client_exception: Unable to execute HTTP request: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target",
        "caused_by": {
          "type": "i_o_exception",
          "reason": "PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target",
          "caused_by": {
            "type": "validator_exception",
            "reason": "validator_exception: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target",
            "caused_by": {
              "type": "sun_cert_path_builder_exception",
              "reason": "sun_cert_path_builder_exception: unable to find valid certification path to requested target"
            }
          }
        }
      }
    }
  },
  "status": 500
}

```

Any hints what to check? I checked JAVA\_HOME is set correctly when ELS starts and also listed content of the cacerts, all seems fine.

---

<div class="post-metadata">

**Author:** ![vaclav1](https://avatars.discourse-cdn.com/v4/letter/v/c68b51/32.png) [@vaclav1](https://discuss.elastic.co/u/vaclav1)\
**Post date:** [June 14, 2021, 12:20pm UTC](https://discuss.elastic.co/t/connecting-to-s3-unable-to-execute-http-request-pkix-path-building-failed/275827/2 "2021-06-14T12:20:43Z")

</div>

Okay, I found the issue.

Try to check all cacerts installation directories:  
`elasticsearch]$ find /* -name cacerts`

`/app/global/java/lib/security/cacerts`

`/app/global/java/bin/cacerts`

`/app/global/java/jre/lib/security/cacerts`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2021, 12:21pm UTC](https://discuss.elastic.co/t/connecting-to-s3-unable-to-execute-http-request-pkix-path-building-failed/275827/3 "2021-07-12T12:21:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
