Repository: Troubleshooting "PKIX path building failed" from proxy repository remote with https – Sonatype Support

Symptoms

The Status of one or more of your proxy repositories that have a remote URL starting with https is:

In service - Remote Automatically Blocked and Unavailable.

The repository was automatically blocked by Nexus Repository because the error indicates:

sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

Summary

This means the trust store that Nexus Repository is using cannot validate the SSL certificates of those remote http URLs.

Normally this does not happen, but examples of when it can happen are:

Please review the specific article for a solution to this scenario.

Solution

First, make sure you are using the latest JDK version supported so that your root certificates are up to date.

You can explicitly examine and trust the remote certificate by

  1. From Nexus UI, go to Server Administration -> Repository -> Repositories. Select the repository with the problem.
  2. Under the " Use the Nexus Repository truststore" section, Click on the " View certificate" button triggers the display of the remote SSL certificate details in a dialog. Examine it closely. If you want to trust the cert, click on " Add certificate to truststore" button. Also ensure " Use the Nexus Repository truststore" checkbox is checked.

Further details are documented in Outbound SSL - Trusting SSL Certificates of Remote Repositories.