Error "PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException:" while trying to deploy new VM in VMware Cloud Director.
search cancel

Error "PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException:" while trying to deploy new VM in VMware Cloud Director.

book

Article ID: 415326

calendar_today

Updated On:

Products

VMware Cloud Director

Issue/Introduction

The below errors are encountered while trying to deploy a new vApp/VM in VCD after renewing the NSX endpoint certificate:

PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target - unable to find valid certification path to requested target; majorErrorCode=500; minorErrorCode=INTERNAL_SERVER_ERROR;

Environment

VMware Cloud Director 10.5.x
VMware Cloud Director 10.6.x

Cause

This issue occurs if NSX certificate is not trusted by VCD

Resolution

In order to resolve this issue, 
1. Ensure that the associated NSX's certificate is not expired and it is trusted by Cloud Director.
2. Refer to the Trusted Certificates section: Provider UI -> Administration -> Certificate Management -> Trusted Certificates, to verify if the NSX certificate is valid and not expired.
3. If the NSX certificate is expired, renew the same by referring to the document Replace Certificates
4. To trust the updated NSX certificate in Cloud Director, login to the provider portal. Navigate to Resources -> Infrastructure Resources -> NSX-T -> NSX-T Managers. Click on the NSX-T manager -> Edit. Provide the Username and password and save the details. 
5. After providing the credentials and clicking Save, the updated certificate will appear. Accept the certificate and save the connection.