Unable to access S3 bucket due to certificate validation failure
Applies to
- Ontap 9
- Ontap S3
Issue
Error on Kubernetes Pod system using S3 server.
level=info ts=2025-04-10T08:10:57.668886951Z caller=flush.go:304 component=ingester msg="flushing stream" user=application fp=7b5128788ed2b083 immediate=true num_chunks=1 total_comp="1.8 MB" avg_comp="1.8 MB" total_uncomp="17 MB" avg_uncomp="17 MB" forced=1 labels="{kubernetes_container_name=\"name\", kubernetes_host=\"host.ocpcorpuat.abc.com\", kubernetes_namespace_name=\"name-xx-wms\", kubernetes_pod_name=\"name\", log_type=\"application\"}"level=error ts=2025-04-10T08:10:57.709360403Z caller=flush.go:261 component=ingester loop=3 org_id=application msg="failed to flush" retries=2 err="failed to flush chunks: store put chunk: RequestError: send request failed\ncaused by: Put \"https://SVMS3.abc.com/bucket1/applic...44%3Ad387f13f\": tls: failed to verify certificate: x509: certificate signed by unknown authority, num_chunks: 1, labels: {kubernetes_container_name=\"name\", kubernetes_host=\"host.ocpcorpuat.abc.com\", kubernetes_namespace_name=\"name-xx-wms\", kubernetes_pod_name=\"name\", log_type=\"application\"}"Error on AWS SDK environments
Error: software.amazon.awssdk.core.exception.SdkClientException: Unable to execute HTTP request: com.domain.jsse2.util.k: PKIX path building failed: com.domain.security.cert.IBMCertPathBuilderException: unable to find valid certification path to requested target (SDK Attempt Count: 4)