IBM Support

IV93825: MISSING DIGICERT GLOBAL ROOT G2 (GLOBALROOTCAG2) CERTIFICATE IN CACERTS

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Error Message: java.security.cert.CertPathBuilderException:
    PKIXCertPathBuilderImpl could not build a valid CertPath.;
    internal cause is:
        java.security.cert.CertPathValidatorException: The
    certificate issued by CN=DigiCert Global Root G2,
    OU=www.digicert.com, O=DigiCert Inc, C=US is not trusted;
    internal cause is:
        java.security.cert.CertPathValidatorException: Certificate
    chaining error
    javax.net.ssl.SSLHandshakeException: com.ibm.jsse2.util.h: PKIX
    path building failed:
    java.security.cert.CertPathBuilderException:
    PKIXCertPathBuilderImpl could not build a valid CertPath.;
    internal cause is:
        java.security.cert.CertPathValidatorException: The
    certificate issued by CN=DigiCert Global Root G2,
    OU=www.digicert.com, O=DigiCert Inc, C=US is not trusted;
    .
    Stack Trace: java.security.cert.CertPathValidatorException:
    Certificate chaining error
        at com.ibm.jsse2.j.a(j.java:12)
        at com.ibm.jsse2.as.a(as.java:118)
        at com.ibm.jsse2.C.a(C.java:193)
        at com.ibm.jsse2.C.a(C.java:245)
        at com.ibm.jsse2.D.a(D.java:242)
        at com.ibm.jsse2.D.a(D.java:56)
        at com.ibm.jsse2.C.r(C.java:69)
        at com.ibm.jsse2.C.a(C.java:580)
        at com.ibm.jsse2.as.a(as.java:512)
        at com.ibm.jsse2.as.i(as.java:969)
        at com.ibm.jsse2.as.a(as.java:680)
        at com.ibm.jsse2.as.startHandshake(as.java:859)
        at
    com.ibm.net.ssl.www2.protocol.https.c.afterConnect(c.java:16)
        at com.ibm.net.ssl.www2.protocol.https.d.connect(d.java:44)
        at
    sun.net.www.protocol.http.HttpURLConnection.getInputStream0(Http
    URLConnection.java:1561)
        at
    sun.net.www.protocol.http.HttpURLConnection.getInputStream(HttpU
    RLConnection.java:1489)
        at
    java.net.HttpURLConnection.getResponseCode(HttpURLConnection.jav
    a:491)
    .
    

Local fix

Problem summary

  • The CertPathValidatorException was thrown as globalrootcag2 is
    missing in the cacerts.
    

Problem conclusion

  • The JDK has been updated to add the missing certificate
    .
    This APAR will be fixed in the following Java Releases:
       8    SR4 FP5   (8.0.4.5)
       6    SR16 FP45 (6.0.16.45)
       7 R1 SR4 FP5   (7.1.4.5)
       7    SR10 FP5  (7.0.10.5)
       6 R1 SR8 FP45  (6.1.8.45)
    .
    Contact your IBM Product's Service Team for these Service
    Refreshes and Fix Packs.
    For those running stand-alone, information about the available
    Service Refreshes and Fix Packs can be found at:
               https://www.ibm.com/developerworks/java/jdk/
    

Temporary fix

Comments

APAR Information

  • APAR number

    IV93825

  • Reported component name

    JAVA CLASS LIBS

  • Reported component ID

    620700130

  • Reported release

    800

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt / Xsystem

  • Submitted date

    2017-03-01

  • Closed date

    2017-04-24

  • Last modified date

    2017-04-24

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    JAVA CLASS LIBS

  • Fixed component ID

    620700130

Applicable component levels

  • R800 PSY

       UP

  • R600 PSY

       UP

  • R700 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSNVBF","label":"Runtimes for Java Technology"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.0","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
21 February 2022