# S\_s\_l\_handshake\_exception in watcher

**URL:** <https://discuss.elastic.co/t/s-s-l-handshake-exception-in-watcher/317307>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-reporting, elastic-stack-alerting\
**Created:** [October 24, 2022, 10:03am UTC](https://discuss.elastic.co/t/s-s-l-handshake-exception-in-watcher/317307 "2022-10-24T10:03:05Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![irivas95](https://avatars.discourse-cdn.com/v4/letter/i/839c29/32.png) [@irivas95](https://discuss.elastic.co/u/irivas95)\
**Post date:** [October 24, 2022, 10:03am UTC](https://discuss.elastic.co/t/s-s-l-handshake-exception-in-watcher/317307/1 "2022-10-24T10:03:05Z")

</div>

Hi,  
I am trying to create the following watcher to send automatically a csv report coming from the POST url of a saved search of kibana. The whatcher is the following:

```auto
{
  "trigger": {
    "schedule": {
      "interval": "2m"
    }
  },
  "input": {
    "none": {}
  },
  "condition": {
    "always": {}
  },
  "actions": {
    "email_admin": {
      "email": {
        "profile": "standard",
        "attachments": {
          "report.csv": {
            "reporting": {
              "url": "https://XXXXXX:5601/api/reporting/generate/csv_searchsource?jobParams=.....",
              "auth": {
                "basic": {
                  "username": "xxxxxx",
                  "password": "xxxxxx"
                }
              }
            }
          }
        },
        "to": [
          "XXXXX@xxxxxx.com"
        ],
        "subject": "report"
      }
    }
  }
}

```

y el error es el siguiente:

```auto
    "actions": [
      {
        "id": "email_admin",
        "type": "email",
        "status": "failure",
        "error": {
          "root_cause": [
            {
              "type": "s_s_l_handshake_exception",
              "reason": "PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target"
            }
          ],
          "type": "s_s_l_handshake_exception",
          "reason": "PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target",
          "caused_by": {
            "type": "validator_exception",
            "reason": "PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target",
            "caused_by": {
              "type": "sun_cert_path_builder_exception",
              "reason": "unable to find valid certification path to requested target"
            }
          }
        }
      }
    ]
  },

```

as you can see it is a certificate error but I don't know where the problem really is, to give more context:  
I have a whole cluster of several nodes with security enabled and they have certificates created from the elastic elasticsearch-certutil tool, so they are self-signed certificates. On the other hand, kibana uses a certificate signed by digicert as ssl server. My configuration in elasticsearch.yml:

```auto
xpack.security.enabled: true

# Enable encryption and mutual authentication between cluster nodes

xpack.security.transport.ssl:
  enabled: true
  verification_mode: certificate
  certificate: certs/node01.crt
  key: certs/node01.key
  certificate_authorities: certs/ca.crt

# Enable encryption for HTTP API client connections, such as Kibana, Logstash, and Agents

xpack.security.http.ssl:
  enabled: true
  verification_mode: certificate
  certificate: certs/node01.crt
  key: certs/node01.key
  certificate_authorities: ["certs/ca.crt"]

```

and my kibana.yml configuration:

```auto
server.ssl.enabled: true
server.ssl.certificate: certs/kibana_digicert.crt
server.ssl.key: certs/kibana_digicert.key

elasticsearch.ssl.certificateAuthorities: ["certs/ca.crt"]

```

Could someone help me to understand what is happening?  
Thanks in advance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 21, 2022, 10:03am UTC](https://discuss.elastic.co/t/s-s-l-handshake-exception-in-watcher/317307/2 "2022-11-21T10:03:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
