Skip to main content

Support Article

Failed to get JWK keys error



Error message displays on updating a Keystore URL in a Keystore rule.

Error Messages

Keystore source URL - Failed to get JWK Keys on the UI

The below error is generated in the PegaRULES.log:

(internal.util.KeyStoreUtilsImpl) ERROR - Failed to get JWK Keys PKIX path building failed: Caused by: unable to find valid certification path to requested target 
    at ~[?:1.8.0_171]

Steps to Reproduce

  1. Create a Keystore rule.
  2. Select Reference to URL.
  3. Add the JSON Web Key (JWK) key endpoint URL which the external identity server provides.

Root Cause

The Pega server JVM does not have the certificate from the external identity server in its TrustStore.


Add the full certificate chain (ROOT  and intermediate) to the Pega application server JVM cacerts.
Suggest Edit

Published November 19, 2019 - Updated March 10, 2020

Did you find this content helpful? Yes No

100% found this useful

Have a question? Get answers now.

Visit the Collaboration Center to ask questions, engage in discussions, share ideas, and help others.

Ready to crush complexity?

Experience the benefits of Pega Community when you log in.

We'd prefer it if you saw us at our best.

Pega Community has detected you are using a browser which may prevent you from experiencing the site as intended. To improve your experience, please update your browser.

Close Deprecation Notice
Contact us