# Handshake error attaching report

**URL:** <https://discuss.elastic.co/t/handshake-error-attaching-report/242497>\
**Category:** Kibana\
**Created:** [July 24, 2020, 10:44am UTC](https://discuss.elastic.co/t/handshake-error-attaching-report/242497 "2020-07-24T10:44:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![uxssmango](https://avatars.discourse-cdn.com/v4/letter/u/a8b319/32.png) [@uxssmango](https://discuss.elastic.co/u/uxssmango)\
**Post date:** [July 24, 2020, 10:44am UTC](https://discuss.elastic.co/t/handshake-error-attaching-report/242497/1 "2020-07-24T10:44:50Z")

</div>

Hello,  
We have a problem trying to attach a report file generated from Kibana.  
Our Kibana web is published through SSL with a wildcard certificate with a valid CA and the error reports:

```auto
      "actions" : [
        {
          "id" : "send_email",
          "type" : "email",
          "status" : "failure",
          "error" : {
            "root_cause" : [
              {
                "type" : "s_s_l_handshake_exception",
                "reason" : "PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target"
              }
            ],
            "type" : "s_s_l_handshake_exception",
            "reason" : "PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target",
            "caused_by" : {
              "type" : "validator_exception",
              "reason" : "PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target",
              "caused_by" : {
                "type" : "sun_cert_path_builder_exception",
                "reason" : "unable to find valid certification path to requested target"
              }
            }
          }

```

We have activated in elasticsearch.yml file:  
`xpack.security.transport.ssl.verification_mode: certificate`  
`xpack.http.ssl.verification_mode: certificate`

Is there any way to avoid validation of the hostname when trying to validate the certificate?

thanks!

---

<div class="post-metadata">

**Author:** ![jportner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jportner/32/75692_2.png) [@jportner](https://discuss.elastic.co/u/jportner)\
**Post date:** [July 27, 2020, 4:46pm UTC](https://discuss.elastic.co/t/handshake-error-attaching-report/242497/2 "2020-07-27T16:46:44Z")

</div>

Hi @uxssmango,

It appears that the error you're seeing is not because of the SSL connection to Kibana, rather it's because of the SSL connection to the mail server.

See [Watcher Email TLS/SSL settings](https://www.elastic.co/guide/en/elasticsearch/reference/7.8/notification-settings.html#ssl-notification-smtp-settings), if you want to disable hostname verification ( **not recommended** ) the correct setting would be:

```auto
xpack.notification.email.ssl.verification_mode: certificate

```

However, I believe what you should do is obtain the CA certificate that was used to sign the mail server's SSL certificate, and configure Elasticsearch to trust that CA:

```auto
xpack.notification.email.ssl.certificate_authorities: ['/path/to/your/ca-cert.pem']

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2020, 4:46pm UTC](https://discuss.elastic.co/t/handshake-error-attaching-report/242497/3 "2020-08-24T16:46:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
