Problem: Invalid certificate error:

If you receive this error: " PKIX path building failed: unable to find valid certification path to requested target)", perform the following steps:

  1. Log on to OWA using http://host/exchange/user.
  2. An invalid certificate message will be shown.
  3. Click on the Invalid Certificate button and press View Certificate.
  4. Go to the Details tab.
  5. Select Copy to File at the bottom. The Export wizard will appear.
  6. Select the first option, DER -encoded binary.
  7. Save to C:\.
    Important: The Certificate CN name must be the fully qualified domain name (i.e. server.domain.ext) of the Exchange server.
  8. Import the certificate that was saved in step 7 into the JRE certificate keystore in %JAVA_HOME%\jre\lib\security\cacerts.For JBoss:
    %JAVA_HOME%\jre\bin\keytool -import -trustcacerts -alias server_name -file 
    certificate.cer -keystore dir\cacerts -storepass changeit
    For WebSphere:
    %WAS_HOME%\java\jre\bin\keytool -import -trustcacerts -alias server_name -file 
    certificate.cer -keystore dir\cacerts -storepass changeit
    Important: server_name for the -alias parameter can be any arbitrary name used to reference this certificate from the cacerts file. certificate.cer should be the full path to the certificate file. dir is %JAVA_HOME%\jre\lib\security\cacerts for JBoss and %WAS_HOME%\java\jre\lib\security\cacerts for Websphere.
    Debug the certificate handling by specifying the system property in the server Process Definition/JVM Custom Properties.
  9. Verify the import was successful by running the following command:
    keytool -list -alias server_name -keystore dir\cacerts -storepass changeit
  10. If using WebSphere, the certificate file must be added to websphere truststore using the WAS Admin Console.
  11. Restart the application server.