Support Article
SAML error: Path does not chain with any of the trust anchors
SA-44174
Summary
SAML 2 processing error related to certificate path validation.
Error Messages
Caused by: org.apache.wss4j.common.ext.WSSecurityException: Error during certificate path validation: Path does not chain with any of the trust anchors
Original Exception was java.security.cert.CertPathValidatorException: Path does not chain with any of the trust anchors
...
Error while executing the Authentication Service activity : Unable to process SAML2 Authentication response : Caught Exception while validating SAML2 Authentication response protocol : Error during certificate path validation: Path does not chain with any of the trust anchors
Steps to Reproduce
Launch the application portal through Single Sign-on (SSO).
Root Cause
A software use or operation error.
In the SAML 2.0 Authentication service, in the Identity Provider (IDP) information section, the Verification certificate used was missing the complete issuer certificate chain.
Resolution
Perform the following local-change:
Update the IDP truststore SAMLAuthIDPCertStore and add the complete issuer certificate chain.
Published February 4, 2018 - Updated October 8, 2020
Have a question? Get answers now.
Visit the Collaboration Center to ask questions, engage in discussions, share ideas, and help others.