PowerProtect: Details in vSphere Web Client Shows PKIX Path Building Exception
Summary: The vCenter vSphere Web Client virtual machine (VM) summary tab PowerProtect details shows an exception indicating that it is unable to find a valid certification path.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
The PowerProtect VM Direct Engine solution is used to protect the vSphere environment. The vCenter vSphere Web Client virtual machine (VM) summary tab shows an error under the PowerProtect details plug-in.
org.springframework.web.client.ResourceAccessException: I/O error on POST request for "https://my-vcenter.mydomain.com/api/ui/vcenter/session/clone-ticket": PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target; nested exception is javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
The
vmware-plugin*log shows:
YYYY-MM-DD HH:MM:SS ERROR [] [https-jsse-nio-0.0.0.0-8459-exec-10] [][][][][] [c.e.b.v.p.g.SessionService.getPluginVimPort(162)] - Exception com.google.common.util.concurrent.UncheckedExecutionException: org.springframework.web.client.ResourceAccessException: I/O error on POST request for "https://my-vcenter.mydomain.com/api/ui/vcenter/session/clone-ticket": PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target; nested exception is javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target at com.google.common.cache.LocalCache$Segment.get(LocalCache.java:2055) ... at java.base/java.lang.Thread.run(Thread.java:829) Caused by: org.springframework.web.client.ResourceAccessException: I/O error on POST request for "https://my-vcenter.mydomain.com/api/ui/vcenter/session/clone-ticket": PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target; nested exception is javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target at org.springframework.web.client.RestTemplate.doExecute(RestTemplate.java:785) ... at com.google.common.cache.LocalCache$Segment.get(LocalCache.java:2049) ... 78 common frames omitted Caused by: javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target at java.base/sun.security.ssl.Alert.createSSLException(Alert.java:131) ... at org.springframework.web.client.RestTemplate.doExecute(RestTemplate.java:776) ... 86 common frames omitted Caused by: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target at java.base/sun.security.validator.PKIXValidator.doBuild(PKIXValidator.java:439) ... at java.base/sun.security.ssl.CertificateMessage$T12CertificateConsumer.checkServerCerts(CertificateMessage.java:638) ... 113 common frames omitted Caused by: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target at java.base/sun.security.provider.certpath.SunCertPathBuilder.build(SunCertPathBuilder.java:141) ... at java.base/sun.security.validator.PKIXValidator.doBuild(PKIXValidator.java:434) ... 121 common frames omitted YYYY-MM-DD HH:MM:SS ERROR [] [https-jsse-nio-0.0.0.0-8459-exec-10] [][][][][] [c.e.b.v.p.f.AuthenticationFilter.doFilter(73)] - Authentication Failed. org.springframework.security.authentication.AuthenticationServiceException: org.springframework.web.client.ResourceAccessException: I/O error on POST request for "https://my-vcenter.mydomain.com/api/ui/vcenter/session/clone-ticket": PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target; nested exception is javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target at com.emc.brs.vmware.plugin.gateway.SessionService.getPluginVimPort(SessionService.java:163) ...
Cause
The vSphere environment contains multiple vCenter servers in vCenter Enhanced Linked Mode. The vCenter Linked servers are managed by different PowerProtect appliances and have the vSphere plug-in option selected. The exception is generated when authenticating to a vCenter that is not managed PowerProtect Appliance vSphere plug.
This issue is not affecting the backup and restore functionality but does not allow vSphere users to run the PowerProtect plug-in features when authenticating to the other vCenters.
This issue is not affecting the backup and restore functionality but does not allow vSphere users to run the PowerProtect plug-in features when authenticating to the other vCenters.
Resolution
To work around the symptom, import all the vCenter Enhanced Linked Mode server certificates to the PowerProtect appliances. The vCenter Server may be added as vCenter Asset Sources in the PowerProtect Interface, which automatically imports the certificate. To add the certificates without adding the vCenter Asset Source, contact Dell Support to use the goppdm command-line utility.
Article Properties
Article Number: 000205840
Article Type: Solution
Last Modified: 26 Mar 2026
Version: 3
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.