KB Article #178408

EBICS: unable to find valid certification path to requested target

Problem

It is an EBICS transfer with a bank. The bank has changed the certificates.

The transfer fails with the following error:

17/01/26 12:30:32 CFTR12I RECV Treated for USER ABC\administrateur <IDTU=A0006OSC PART=CA075 IDF=HPB>

17/01/26 12:30:32 CFTS20I Communication file row number deleted: 00000313

17/01/26 12:30:32 CFTT13I Session parameters <IDTU=A0006OSC PART=CA075 IDF=HPB IDT=A2612303 _ PROT=EBICS_A005_H003 SAP=

17/01/26 12:30:32 CFTT13I+HOST=https://www.bankurl.fr/EBX882/Ebics.rq>

17/01/26 12:30:33 CFTJ00E javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed:

17/01/26 12:30:33 CFTJ00E+sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

17/01/26 12:30:33 CFTT82E transfer aborted <IDTU=A0006OSC PART=CA075 IDF=HPB IDT=A2612303 260 >


Resolution

Take the new certificates from the bank url: https://www.bankurl.fr/EBX882/Ebics.rq

You can enter the URL in Internet Explorer and export them from there.

After this, import the new certificates in the PKI database.

This new certificates are needed to be put in the ROOTCID of the CFTSSL – type CLIENT object, associated to the bank partner, CFTPART object.

Now the bank certificates had changed, you need to re-do the INIHIA command.

Exemple:

CFTUTIL SEND PART=BANK0, IDF=INIHIA, SUSER= USER_ID