# "PKIX path validation failed: java.security.cert.CertPathValidatorException: validity check failed"

**URL:** https://discuss.elastic.co/t/pkix-path-validation-failed-java-security-cert-certpathvalidatorexception-validity-check-failed/368360
**Category:** Logstash
**Created:** [October 7, 2024, 4:02pm UTC](https://discuss.elastic.co/t/pkix-path-validation-failed-java-security-cert-certpathvalidatorexception-validity-check-failed/368360 "2024-10-07T16:02:54Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![apal](https://avatars.discourse-cdn.com/v4/letter/a/bc8723/32.png) [@apal](https://discuss.elastic.co/u/apal)
#### Post date: [October 7, 2024, 4:02pm UTC](https://discuss.elastic.co/t/pkix-path-validation-failed-java-security-cert-certpathvalidatorexception-validity-check-failed/368360/1 "2024-10-07T16:02:54Z")

</div>

Here's the full error:

```auto
Oct 07 11:57:38 elk.example.com logstash[3697608]: [2024-10-07T11:57:38,571][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"https://logstash_internal:xxxxxx@elk.example.com:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :message=>"Elasticsearch Unreachable: [https://elk.example.com:9200/][Manticore::ClientProtocolException] PKIX path validation failed: java.security.cert.CertPathValidatorException: validity check failed"}

```

It was working fine till about 09:45 today morning after which it started showing up with this. I use the same `ca.crt` for both Elasticsearch and Logstash and have `chowned` and `setfacl`ed the respective directories (I do not think this is a problem with permissions). `ca.crt` is valid till 2035.

Can someone help me? I have seen many similar errors but this specifically never turned up in my search.

The only things I have changed from the default `logstash.yml` are:

- 

```auto
   path.data: /usr/share/logstash/data

```

- `pipeline.id: main`

Thanks

* * *

Edit: Relevant part of my pipeline config

```auto
output {
  stdout { codec => rubydebug }
  elasticsearch {
    hosts => ["https://elk.example.com:9200"]
    index => "%{log_index}"
    action => "create"
    ssl_certificate_authorities => "/etc/logstash/ssl/ca.crt"
    ssl => true
    user => "logstash_internal"
    password => <some password>
  }
}

```

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [October 7, 2024, 4:52pm UTC](https://discuss.elastic.co/t/pkix-path-validation-failed-java-security-cert-certpathvalidatorexception-validity-check-failed/368360/2 "2024-10-07T16:52:53Z")

</div>

> [@apal](#):
>
> It was working fine till about 09:45 today morning

What timezone are you in?

The most common reason for that error seems to be that one of the certificates in the validation chain has expired.

---

<div class="post-metadata">

### Author: ![apal](https://avatars.discourse-cdn.com/v4/letter/a/bc8723/32.png) [@apal](https://discuss.elastic.co/u/apal)
#### Post date: [October 7, 2024, 5:06pm UTC](https://discuss.elastic.co/t/pkix-path-validation-failed-java-security-cert-certpathvalidatorexception-validity-check-failed/368360/3 "2024-10-07T17:06:32Z")

</div>

Hello, I'm in EST in the US.

You're probably right. A few other things broke in our infrastructure for similar reasons and looks like the cert is the problem. I will be investigating this today, will get back once I (attempt to) fix this.

Thanks

---

<div class="post-metadata">

### Author: ![apal](https://avatars.discourse-cdn.com/v4/letter/a/bc8723/32.png) [@apal](https://discuss.elastic.co/u/apal)
#### Post date: [October 8, 2024, 1:17pm UTC](https://discuss.elastic.co/t/pkix-path-validation-failed-java-security-cert-certpathvalidatorexception-validity-check-failed/368360/4 "2024-10-08T13:17:37Z")

</div>

Unfortunately, that doesn't seem to have fixed the problem. I replaced the cert with a new cert (the previous one had already expired). Both of these certs are derived from an intermediate certificate.

What am I missing? This is my Elasticsearch config:

```auto
xpack.security.http.ssl:
  enabled: true
  key: ssl/elk.example.com.key
  certificate: ssl/elk.example.com.crt
  certificate_authorities: ssl/ca.crt

xpack.security.transport.ssl:
  enabled: true
  verification_mode: none
  key: ssl/elk.example.com.key
  certificate: ssl/elk.example.com.crt
  certificate_authorities: ssl/ca.crt

```

(`ssl` is a subdirectory in `/etc/elasticsearch` and `elk.example.com.crt` has been replaced by a new cert which is valid. I did not rotate the private key.

* * *

Edit: complete error log from Logstash:

```auto
Oct 08 09:20:21 elk.example.com logstash[4120966]: [2024-10-08T09:20:21,670][INFO][logstash.outputs.elasticsearch][main] Failed to perform request {:message=>"Invalid CertificateVerify signature", :exception=>Manticore::ClientProtocolException, :cause=>#<Java::JavaxNetSsl::SSLHandshakeException: Invalid CertificateVerify signature>}

Oct 08 09:20:21 elk.example.com logstash[4120966]: [2024-10-08T09:20:21,671][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"https://logstash_internal:xxxxxx@elk.example.com:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :message=>"Elasticsearch Unreachable: [https://elk.example.com:9200/][Manticore::ClientProtocolException] Invalid CertificateVerify signature"}

```

---

<div class="post-metadata">

### Author: ![apal](https://avatars.discourse-cdn.com/v4/letter/a/bc8723/32.png) [@apal](https://discuss.elastic.co/u/apal)
#### Post date: [October 10, 2024, 8:10pm UTC](https://discuss.elastic.co/t/pkix-path-validation-failed-java-security-cert-certpathvalidatorexception-validity-check-failed/368360/5 "2024-10-10T20:10:57Z")

</div>

Hello,

It seems that there was a problem in the certificate that was generated. I checked the certificate with `openssl` and was seeing Validation Errors. We produced a new certificate for Elasticsearch and now everything is working fine. Hope this helps anyone who comes across this thread in the future.
