# PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

**URL:** <https://discuss.elastic.co/t/pkix-path-building-failed-sun-security-provider-certpath-suncertpathbuilderexception-unable-to-find-valid-certification-path-to-requested-target/378109>\
**Category:** Logstash\
**Created:** [May 14, 2025, 2:26am UTC](https://discuss.elastic.co/t/pkix-path-building-failed-sun-security-provider-certpath-suncertpathbuilderexception-unable-to-find-valid-certification-path-to-requested-target/378109 "2025-05-14T02:26:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ria](https://avatars.discourse-cdn.com/v4/letter/r/d2c977/32.png) [@Ria](https://discuss.elastic.co/u/Ria)\
**Post date:** [May 14, 2025, 2:26am UTC](https://discuss.elastic.co/t/pkix-path-building-failed-sun-security-provider-certpath-suncertpathbuilderexception-unable-to-find-valid-certification-path-to-requested-target/378109/1 "2025-05-14T02:26:00Z")

</div>

I'm using http\_poller input plugin in the logstash pipeline in order to ingest the REST API endpoint call response to feed into the elasticsearch index .This is my current configuration of the pipeline as I'm doing on my work device.

```auto
input {
  http_poller {
    urls => {
      test1 => {
        method => get
        ssl_enabled => true
        cacert => "C:\Users\882709066\Downloads\logstash-8.12.2\rbc-ca-bundle.pem"
        ssl_certificate => "C:\Users\882709066\Downloads\logstash-8.12.2\rbc-ca-bundle.cer"
        url => "https://volume-prediction-restapi-juc0-private-qat.apps.ocp-sai-s1.saifg.rbc.com/inference"
        headers => {
          "Content-Type" => "application/json"
        }
        body => '{
          "date": "01-03-2025",
          "pred_column": "file_record_count",
          "history_limit_days": 90
        }'
      }
    }
    request_timeout => 60
    schedule => { cron => "* * * * * UTC" } # Runs every minute
    codec => "json" # Parses the JSON response
  }
}

filter {
  # Add your filter logic here if needed
}

output {
  stdout {
    codec => rubydebug
  }
  elasticsearch {
    hosts => ["https://2bac88ffc6b84ebeb6a945337cb56bb9.ece.saifg.rbc.com:9243"]
    user => "elastic"
    password => " ******"
    ilm_rollover_alias => "test-api"
    ssl => true
    ssl_certificate_verification => true
    cacert => "C:/Users/882709066/Downloads/logstash-8.12.2/elastic-cert.cer"
  }
}

```

Kindly please help in resolving this error as I tried various options but unable to resolve.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 14, 2025, 9:30am UTC](https://discuss.elastic.co/t/pkix-path-building-failed-sun-security-provider-certpath-suncertpathbuilderexception-unable-to-find-valid-certification-path-to-requested-target/378109/2 "2025-05-14T09:30:33Z")

</div>

> [@Ria](#):
>
> ```
> cacert => "C:\Users\882709066\Downloads\logstash-8.12.2\rbc-ca-bundle.pem"
> ssl_certificate => "C:\Users\882709066\Downloads\logstash-8.12.2\rbc-ca-bundle.cer"
> 
> ```

Welcome to the community.

Have you try to use forward slashes / for the input http\_poller

`cacert => "C:/Users/882709066/Downloads/logstash-8.12.2/rbc-ca-bundle.pem"`

If is still not work, can you copy more details from the log/debug.

---

<div class="post-metadata">

**Author:** ![Ria](https://avatars.discourse-cdn.com/v4/letter/r/d2c977/32.png) [@Ria](https://discuss.elastic.co/u/Ria)\
**Post date:** [May 14, 2025, 1:22pm UTC](https://discuss.elastic.co/t/pkix-path-building-failed-sun-security-provider-certpath-suncertpathbuilderexception-unable-to-find-valid-certification-path-to-requested-target/378109/3 "2025-05-14T13:22:25Z")

</div>

Hi @Rios , Itried using the forward slashes too but no luck. I'm attaching the logs while running the logstash in my local.

```auto
{
         "error" => {
        "stack_trace" => nil,
            "message" => "PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target"
    },
      "@version" => "1",
         "event" => {
        "duration" => 165000
    },
           "url" => {
        "full" => "https://volume-prediction-restapi-juc0-private-qat.apps.ocp-sai-s1.saifg.rbc.com/inference"
    },
    "@timestamp" => 2025-05-14T07:22:00.819956400Z,
          "http" => {
        "request" => {
            "method" => "get"
        }
    },
          "tags" => [
        [0] "_http_request_failure"
    ],
          "host" => {
        "hostname" => "KZBWB43S"

```

---

<div class="post-metadata">

**Author:** ![Ria](https://avatars.discourse-cdn.com/v4/letter/r/d2c977/32.png) [@Ria](https://discuss.elastic.co/u/Ria)\
**Post date:** [May 15, 2025, 12:09am UTC](https://discuss.elastic.co/t/pkix-path-building-failed-sun-security-provider-certpath-suncertpathbuilderexception-unable-to-find-valid-certification-path-to-requested-target/378109/4 "2025-05-15T00:09:31Z")

</div>

Can anyone from #Elastic team help me ?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 15, 2025, 6:31am UTC](https://discuss.elastic.co/t/pkix-path-building-failed-sun-security-provider-certpath-suncertpathbuilderexception-unable-to-find-valid-certification-path-to-requested-target/378109/5 "2025-05-15T06:31:16Z")

</div>

You have used [the obsolete](https://www.elastic.co/docs/reference/logstash/plugins/plugins-inputs-http_poller#plugins-inputs-http_poller-obsolete-options) param, try with:

```auto
        ssl_enabled => true
        ssl_certificate_authorities => "C:\Users\882709066\Downloads\logstash-8.12.2\rbc-ca-bundle.pem"
        ssl_verification_mode => "full" # "none"

```

If still is the problem there, try with none. _The `none` setting performs no verification of the server’s certificate._

`ssl_certificate` - Do you really need a client certificate? If do, you need also `ssl_key`
