# SDK cannot reach AWS S3 repository after upgrading to ES 6.3.0

**URL:** <https://discuss.elastic.co/t/sdk-cannot-reach-aws-s3-repository-after-upgrading-to-es-6-3-0/135895>\
**Category:** Elasticsearch\
**Created:** [June 14, 2018, 10:09am UTC](https://discuss.elastic.co/t/sdk-cannot-reach-aws-s3-repository-after-upgrading-to-es-6-3-0/135895 "2018-06-14T10:09:40Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mr.King](https://avatars.discourse-cdn.com/v4/letter/m/bbe5ce/32.png) [@Mr.King](https://discuss.elastic.co/u/Mr.King)\
**Post date:** [June 14, 2018, 10:09am UTC](https://discuss.elastic.co/t/sdk-cannot-reach-aws-s3-repository-after-upgrading-to-es-6-3-0/135895/1 "2018-06-14T10:09:40Z")

</div>

I upgraded from ES 6.2.3 to 6.3.0 and my whole cluster cannot reach my AWS S3 bucket anymore.  
Notice that I use the ES docker build.

> GET \_snapshot/elk-repo/\*  
> {  
> "error": {  
> "root\_cause": [  
> {  
> "type": "repository\_missing\_exception",  
> "reason": "[elk-repo] missing"  
> }  
> ],  
> "type": "repository\_missing\_exception",  
> "reason": "[elk-repo] missing"  
> },  
> "status": 404  
> }

When I want to create my repo:

> PUT \_snapshot/elk-repo  
> {  
> "type": "s3",  
> "settings":  
> {  
> "bucket": "elasticsearch-snapshots",  
> "base\_path": "elk"  
> }  
> }

I got the following error:

> {  
> "error": {  
> "root\_cause": [  
> {  
> "type": "sdk\_client\_exception",  
> "reason": "sdk\_client\_exception: Unable to execute HTTP request: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target"  
> }  
> ],  
> "type": "repository\_exception",  
> "reason": "[elk-repo] failed to create repository",  
> "caused\_by": {  
> "type": "sdk\_client\_exception",  
> "reason": "sdk\_client\_exception: Unable to execute HTTP request: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target",  
> "caused\_by": {  
> "type": "i\_o\_exception",  
> "reason": "sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target",  
> "caused\_by": {  
> "type": "validator\_exception",  
> "reason": "validator\_exception: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target",  
> "caused\_by": {  
> "type": "sun\_cert\_path\_builder\_exception",  
> "reason": "sun\_cert\_path\_builder\_exception: unable to find valid certification path to requested target"  
> }  
> }  
> }  
> }  
> },  
> "status": 500  
> }

I tried to create a brand new container multiple time but I have the same error.

---

<div class="post-metadata">

**Author:** ![Mr.King](https://avatars.discourse-cdn.com/v4/letter/m/bbe5ce/32.png) [@Mr.King](https://discuss.elastic.co/u/Mr.King)\
**Post date:** [June 20, 2018, 7:17am UTC](https://discuss.elastic.co/t/sdk-cannot-reach-aws-s3-repository-after-upgrading-to-es-6-3-0/135895/2 "2018-06-20T07:17:09Z")

</div>

It seems this error is related to bad SSL certificates but it is a new install from the docker build. Any idea please?

---

<div class="post-metadata">

**Author:** ![tebriel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tebriel/32/44889_2.png) [@tebriel](https://discuss.elastic.co/u/tebriel)\
**Post date:** [July 2, 2018, 8:01pm UTC](https://discuss.elastic.co/t/sdk-cannot-reach-aws-s3-repository-after-upgrading-to-es-6-3-0/135895/3 "2018-07-02T20:01:13Z")

</div>

I'm also experiencing this with the EC2 Discovery plugin using the 6.3.0 docker.

> [2018-07-02T19:59:07,643][INFO][o.e.d.e.AwsEc2UnicastHostsProvider] [9WyEXt5] Exception while retrieving instance list from AWS API: Unable to execute HTTP request: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

I've reverted to 6.2.4 for now.

---

<div class="post-metadata">

**Author:** ![tebriel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tebriel/32/44889_2.png) [@tebriel](https://discuss.elastic.co/u/tebriel)\
**Post date:** [July 3, 2018, 1:52pm UTC](https://discuss.elastic.co/t/sdk-cannot-reach-aws-s3-repository-after-upgrading-to-es-6-3-0/135895/4 "2018-07-03T13:52:06Z")

</div>

[Elasticsearch-Docker Issue #171](https://github.com/elastic/elasticsearch-docker/issues/171) mentions this issue and notes that `docker.elastic.co/elasticsearch/elasticsearch:6.3.0-cacerts` has a fix in it.

---

<div class="post-metadata">

**Author:** ![Mr.King](https://avatars.discourse-cdn.com/v4/letter/m/bbe5ce/32.png) [@Mr.King](https://discuss.elastic.co/u/Mr.King)\
**Post date:** [July 3, 2018, 3:36pm UTC](https://discuss.elastic.co/t/sdk-cannot-reach-aws-s3-repository-after-upgrading-to-es-6-3-0/135895/5 "2018-07-03T15:36:46Z")

</div>

Thank you tebriel.  
I spent hours to find a workaround and finally built my own docker image with the Elasticsearch DEB package.

---

<div class="post-metadata">

**Author:** ![tebriel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tebriel/32/44889_2.png) [@tebriel](https://discuss.elastic.co/u/tebriel)\
**Post date:** [July 3, 2018, 6:00pm UTC](https://discuss.elastic.co/t/sdk-cannot-reach-aws-s3-repository-after-upgrading-to-es-6-3-0/135895/6 "2018-07-03T18:00:21Z")

</div>

Yeah, I tweeted @elastic and they linked me the github issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 31, 2018, 6:00pm UTC](https://discuss.elastic.co/t/sdk-cannot-reach-aws-s3-repository-after-upgrading-to-es-6-3-0/135895/7 "2018-07-31T18:00:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
