I have been having an issue for months where all of the sudden our Java install on Centos 6.10 stopped adding client site certificates to the java keystore. To work around this I need to browse to the clients website such as https://ws.example.com then in firefox or chrome download the certificate. Upload it to the server, then finally use Keytool to install the certificate. This started happening out of the blue, so I am not sure what changed. but would really appreciate someone pointing me in the right direction. This is the error we get in our application:
Exception waiting for response: ; nested exception is: javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target