Skip to main content
Question

IFS Coud - PSO - PKIX path building failed


Darshana Herath
Hero (Former Employee)
Forum|alt.badge.img+14

Hi All,

 

I installed IFS PSO (v6.14) as a standard installation.


Created a self-signed certificate from IIS and configured IIS and PSO is working with the certificate.

 

Then the certificate was added to IFS Cloud(24R2) through ‘ifscloud-values’ file as explained it a KBA.

 

Any Idea on this ?

 

 



 

 

ERROR - 1

Validating IFS Cloud callback URL failed. Error message was: PlsqlapServer.ERRINV: ExecutionException from Sender thread
Caused by: ifs.fnd.connect.senders.ConnectSender$TemporaryFailureException: Exception while sending data
Caused by: javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
Caused by: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderExceptio. If this is an external URL which can be accessed only from IFS Optimization server, it cannot be validated using the configuration assistant. The URL may still work when accessed externally. Do you want to continue?

 

ERROR - 2

Failed to connect to IFS Optimization server account Default. Error message was: com.ifsworld.fnd.odp.api.exception.ProjectionException: javax.ws.rs.ProcessingException: java.net.UnknownHostException: UnknownHostException invoking https://<host>/IFSSchedulingRESTfulGateway/api/v1/scheduling/session: ifscloudmgt. The user SERVICE-ACCOUNT-IFS_SCHEDULING and the parameters OpenIdAuthority, OpenIdClientId, UserNameClaim may need to be set up manually. Do you want to continue?

 

PSO has installed on IFS Cloud management server for testing which is in the same network of the middle tier.


It is showing below errors when finishing the configuration
 

3 replies

roklde
Superhero (Employee)
Forum|alt.badge.img+26
  • Superhero (Employee)
  • 745 replies
  • February 4, 2025

Hi Darshana,

which certificate thumbprint are you using? Make sure to configure the parameter as outlined in following guideline:
 


Best regards
Roman


Darshana Herath
Hero (Former Employee)
Forum|alt.badge.img+14
  • Author
  • Hero (Former Employee)
  • 115 replies
  • February 7, 2025
roklde wrote:

Hi Darshana,

which certificate thumbprint are you using? Make sure to configure the parameter as outlined in following guideline:
 


Best regards
Roman

Hi ​@roklde , I used the thumbprint of IFSCLOUD (24R2) certificate (SSL).
This is a valid certificate (not a self-signed one)

Do we need this thumbprint? since I imported it into container from cloud value file
 


roklde
Superhero (Employee)
Forum|alt.badge.img+26
  • Superhero (Employee)
  • 745 replies
  • February 7, 2025

Hi ​@Darshana Herath !

In that case you would not need to set the thumbprint.

Note that you need to import the certificate of the PSO Server into the OData and Connect deployments. I assume the connection is failing because IFS Cloud rejects it as the certificate of PSO is not known.

Also make sure that you’ve used the FQDN (full qualified domain name) of the PSO Server in the assistant.

The thumbprint that’s configured in the assistant and PSO parameters is for PSO to IFS Cloud communication (e.g. Broadcasts). As said if the IFS Cloud cert is signed by a known-CA you can remove it.

Best regards
Roman


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings