SSLHandshakeException with SMP/E Internet Service Retrieval utility


Article ID: 207092


Updated On:


CA Common Services for z/OS


Downloading the CA certificate for Internet Service Delivery, adding it to the RACF database and to a keyring.

Trying an Internet Service Retrieval (SMP/E RECEIVE ORDER) and getting the following message in the SMPOUT DD: PKIX path building filed: PKIXCertPathBuilderImpl coulnot build a valid CertPath.; internal cause is: The certificate issued by CN=DigitCert Global Root CA,, O=DigiCert Inc, C=US is not trusted;

internal cause is:                                                     Certificate chaining error    


COMMON SERVICES 15.0 - z/OS supported releases - 



DigiCert SHA2 Secure Server CA and DigiCert Global Root CA should be added to the keyring along with the required User certificate.

Downloading those certificates, and adding them to the keyring should resolve this problem.

Related Documentation: Obtain the Certificates for SMP/E Internet Service Retrieval