Changes for page Unable to find valid certification path
                  Last modified by Erik Bakker on 2024/09/03 13:24
              
      
      From version  34.1 
    
    
              edited by Erik Bakker
        
on 2022/06/13 16:05
     on 2022/06/13 16:05
      Change comment:
              Deleted image "rca-knowledgebase-unable-to-find-valid-certification-path--errors-in-emagiz-part-one.png"
          
         Summary
- 
          Page properties (4 modified, 0 added, 0 removed)
- 
          Attachments (0 modified, 1 added, 0 removed)
Details
- Page properties
- 
      - Title
-   ... ... @@ -1,1 +1,0 @@ 1 -Unable to find valid certification path 
- Parent
-   ... ... @@ -1,1 +1,0 @@ 1 -WebHome 
- Author
-   ... ... @@ -1,1 +1,1 @@ 1 -XWiki. ebakker1 +XWiki.marijn 
- Content
-   ... ... @@ -1,18 +1,34 @@ 1 -{{container}}{{container layoutStyle="columns"}}((( 1 +{{html wiki="true"}} 2 +<div class="ez-academy"> 3 + <div class="ez-academy_body"> 4 + 5 +<div class="doc"> 6 + 7 += RCA * Unable to find valid certification path = 8 + 2 2 In this document, we will use the information from the actual root cause analysis to make a generic view that can be used if you run into the same or a similar problem in the future. Finally, the document will describe the situation, the problem, the analysis, and the result. 3 3 4 4 Should you have any questions, please get in touch with academy@emagiz.com. 5 5 6 -== 3. Unable to find valid certification path == 13 +* Last update: March 8th, 2022 14 +* Required reading time: 4 minutes 7 7 16 +===== Situation ===== 17 + 18 +== 3. RCA * Unable to find valid certification path == 19 + 8 8 === 3.1 Situation === 9 9 10 10 On a specific working day, a connection between eMagiz and an external REST service broke down due to errors related to certificate problems. The external party updated the trusted certificates, but they did not notify the client team working on the eMagiz solution. 11 11 24 +===== Problem ===== 25 + 12 12 === 3.2 Problem === 13 13 14 14 As a result of these actions, no data could be supplied to the system before the problem was resolved. 15 15 30 +===== Analysis ===== 31 + 16 16 === 3.3 Analysis === 17 17 18 18 ==== 3.3.1 Errors in eMagiz ==== ... ... @@ -19,9 +19,9 @@ 19 19 20 20 To analyze the problem, we first looked at the errors within the environment to get a sense of the issue at hand. See below for the errors we saw. 21 21 22 - [[image:Main.Images.RCA-Knowledgebase.WebHome@rca-knowledgebase-unable-to-find-valid-certification-path--errors-in-emagiz-part-one.png]]38 +<p align="center">[[image:rca-knowledgebase-unable-to-find-valid-certification-path--errors-in-emagiz-part-one.png||]]</p> 23 23 24 - [[image:Main.Images.RCA-Knowledgebase.WebHome@rca-knowledgebase-unable-to-find-valid-certification-path--errors-in-emagiz-part-two.png]]40 +<p align="center">[[image:rca-knowledgebase-unable-to-find-valid-certification-path--errors-in-emagiz-part-two.png||]]</p> 25 25 26 26 ==== 3.3.2 Call endpoint in Postman with SSL verification on ==== 27 27 ... ... @@ -28,18 +28,20 @@ 28 28 Secondly, we navigated to the endpoint via the browser to determine the certificate chain of the external party. Once we had established the certificate chain, we tested the connection via Postman. 29 29 When calling the external application with SSL verification turned on but no Certificates configured, we get the below error. This indicates that Postman does not trust the external party enough to establish a proper connection. 30 30 31 - [[image:Main.Images.RCA-Knowledgebase.WebHome@rca-knowledgebase-unable-to-find-valid-certification-path--postman-ssl-verification-on.png]]47 +<p align="center">[[image:rca-knowledgebase-unable-to-find-valid-certification-path--postman-ssl-verification-on.png||]]</p> 32 32 33 33 The call works again when we add the intermediate certificate to the list of trusted certificates. 34 34 35 - [[image:Main.Images.RCA-Knowledgebase.WebHome@rca-knowledgebase-unable-to-find-valid-certification-path--postman-ssl-verification-on-configured-cert.png]]51 +<p align="center">[[image:rca-knowledgebase-unable-to-find-valid-certification-path--postman-ssl-verification-on-configured-cert.png||]]</p> 36 36 37 37 ==== 3.3.3 Truststore configuration and configuration in eMagiz ==== 38 38 39 39 With these results, we have added the intermediate and the CA certificate to a custom truststore for the external party and linked the truststore to the HTTP outbound gateway. 40 40 41 - [[image:Main.Images.RCA-Knowledgebase.WebHome@rca-knowledgebase-unable-to-find-valid-certification-path--truststore-config-and-emagiz-config.png]]57 +<p align="center">[[image:rca-knowledgebase-unable-to-find-valid-certification-path--truststore-config-and-emagiz-config.png||]]</p> 42 42 59 +===== Result ===== 60 + 43 43 === 3.4 Result === 44 44 45 45 The analysis concluded that there is a mismatch between the certificates used at the external party and those on default trusted by various software parties (including Java). The best course of action would be to use a certificate structure in which the entire certificate chain (intermediate and CA) is trusted adequately on default. This removes the need for custom configuration in the form of a custom truststore that needs to be managed at the eMagiz side and updated every time the external parties certificate changes. ... ... @@ -46,4 +46,8 @@ 46 46 47 47 When that is impossible, there should be ongoing communication between the external party and the implementation team at the eMagiz environment when certificates are changed or expired. Those moments could trigger the need to change the custom truststore that the integration team must use within the eMagiz model to establish the connection. 48 48 49 -)))((({{toc/}}))){{/container}}{{/container}} 67 +</div> 68 +</div> 69 +</div> 70 + 71 +{{/html}} 
 
- rca-knowledgebase-unable-to-find-valid-certification-path--errors-in-emagiz-part-one.png
-   - Author
-   ... ... @@ -1,0 +1,1 @@ 1 +XWiki.marijn 
- Size
-   ... ... @@ -1,0 +1,1 @@ 1 +16.4 KB 
- Content
 
