# gatling 3.0.1 - SSL problems even with useInsecureTrustManager

**URL:** <https://community.gatling.io/t/gatling-3-0-1-ssl-problems-even-with-useinsecuretrustmanager/4690>\
**Category:** Gatling (Open-Source)\
**Created:** [December 6, 2018, 11:11am UTC](https://community.gatling.io/t/gatling-3-0-1-ssl-problems-even-with-useinsecuretrustmanager/4690 "2018-12-06T11:11:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Flavio\_Campana](https://avatars.discourse-cdn.com/v4/letter/f/94ad74/32.png) [@Flavio\_Campana](https://community.gatling.io/u/Flavio_Campana)\
**Post date:** [December 6, 2018, 11:11am UTC](https://community.gatling.io/t/gatling-3-0-1-ssl-problems-even-with-useinsecuretrustmanager/4690/1 "2018-12-06T11:11:23Z")

</div>

Hi  
I’m having trouble with gatling, we use self signed certs in our test environmente, but even when setting useInsecureTrustManager to true explicitly (it should be default anyway) we still get :

`sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target at sun.security.provider.certpath.SunCertPathBuilder.build(SunCertPathBuilder.java:141) at sun.security.provider.certpath.SunCertPathBuilder.engineBuild(SunCertPathBuilder.java:126) at java.security.cert.CertPathBuilder.build(CertPathBuilder.java:280) at sun.security.validator.PKIXValidator.doBuild(PKIXValidator.java:382) ... 34 common frames omitted Wrapped by: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target at sun.security.validator.PKIXValidator.doBuild(PKIXValidator.java:387) at sun.security.validator.PKIXValidator.engineValidate(PKIXValidator.java:230) at sun.security.validator.Validator.validate(Validator.java:260) at sun.security.ssl.X509TrustManagerImpl.validate(X509TrustManagerImpl.java:324) at sun.security.ssl.X509TrustManagerImpl.checkTrusted(X509TrustManagerImpl.java:281) at sun.security.ssl.X509TrustManagerImpl.checkServerTrusted(X509TrustManagerImpl.java:136) at sun.security.ssl.ClientHandshaker.serverCertificate(ClientHandshaker.java:1501) ... 28 common frames omitted`

Tests are run inside docker with image maven:3-alpine

---

<div class="post-metadata">

**Author:** ![Flavio\_Campana](https://avatars.discourse-cdn.com/v4/letter/f/94ad74/32.png) [@Flavio\_Campana](https://community.gatling.io/u/Flavio_Campana)\
**Post date:** [December 12, 2018, 4:25pm UTC](https://community.gatling.io/t/gatling-3-0-1-ssl-problems-even-with-useinsecuretrustmanager/4690/2 "2018-12-12T16:25:40Z")

</div>

I’m also having troubles recording some https sites:

`

17:24:07.672 [WARN] i.n.c.DefaultChannelPipeline - An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.  
javax.net.ssl.SSLHandshakeException: Received fatal alert: bad\_certificate  
at java.base/sun.security.ssl.Alert.createSSLException(Alert.java:128)  
at java.base/sun.security.ssl.Alert.createSSLException(Alert.java:117)  
at java.base/sun.security.ssl.TransportContext.fatal(TransportContext.java:308)  
at java.base/sun.security.ssl.Alert$AlertConsumer.consume(Alert.java:279)  
at java.base/sun.security.ssl.TransportContext.dispatch(TransportContext.java:181)  
at java.base/sun.security.ssl.SSLTransport.decode(SSLTransport.java:164)  
at java.base/sun.security.ssl.SSLEngineImpl.decode(SSLEngineImpl.java:672)  
at java.base/sun.security.ssl.SSLEngineImpl.readRecord(SSLEngineImpl.java:627)  
at java.base/sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:443)  
at java.base/sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:422)  
at java.base/javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:634)  
at io.netty.handler.ssl.SslHandler$SslEngineType$3.unwrap(SslHandler.java:294)  
at io.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1297)  
at io.netty.handler.ssl.SslHandler.decodeJdkCompatible(SslHandler.java:1199)  
at io.netty.handler.ssl.SslHandler.decode(SslHandler.java:1243)  
at io.netty.handler.codec.ByteToMessageDecoder.decodeRemovalReentryProtection(ByteToMessageDecoder.java:502)  
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:441)  
… 16 common frames omitted  
Wrapped by: io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: Received fatal alert: bad\_certificate  
at io.netty.handler.codec.ByteToMessageDecoder.callDecode(ByteToMessageDecoder.java:472)  
at io.netty.handler.codec.ByteToMessageDecoder.channelRead(ByteToMessageDecoder.java:278)  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362)  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348)  
at io.netty.channel.AbstractChannelHandlerContext.fireChannelRead(AbstractChannelHandlerContext.java:340)  
at io.netty.channel.DefaultChannelPipeline$HeadContext.channelRead(DefaultChannelPipeline.java:1434)  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:362)  
at io.netty.channel.AbstractChannelHandlerContext.invokeChannelRead(AbstractChannelHandlerContext.java:348)  
at io.netty.channel.DefaultChannelPipeline.fireChannelRead(DefaultChannelPipeline.java:965)  
at io.netty.channel.nio.AbstractNioByteChannel$NioByteUnsafe.read(AbstractNioByteChannel.java:163)  
at io.netty.channel.nio.NioEventLoop.processSelectedKey(NioEventLoop.java:644)  
at io.netty.channel.nio.NioEventLoop.processSelectedKeysOptimized(NioEventLoop.java:579)  
at io.netty.channel.nio.NioEventLoop.processSelectedKeys(NioEventLoop.java:496)  
at io.netty.channel.nio.NioEventLoop.run(NioEventLoop.java:458)  
at io.netty.util.concurrent.SingleThreadEventExecutor$5.run(SingleThreadEventExecutor.java:897)  
at io.netty.util.concurrent.FastThreadLocalRunnable.run(FastThreadLocalRunnable.java:30)  
at java.base/java.lang.Thread.run(Thread.java:834)

`

---

<div class="post-metadata">

**Author:** ![slandelle](https://dub1.discourse-cdn.com/flex013/user_avatar/community.gatling.io/slandelle/32/4_2.png) [@slandelle](https://community.gatling.io/u/slandelle)\
**Post date:** [December 12, 2018, 4:30pm UTC](https://community.gatling.io/t/gatling-3-0-1-ssl-problems-even-with-useinsecuretrustmanager/4690/3 "2018-12-12T16:30:07Z")

</div>

Your problem has noting to do with the TrustManager (how you decide to trust the cert issuer).  
Your problem is that your certificate is simply invalid. Maybe it’s not valid for your hostname.

---

<div class="post-metadata">

**Author:** ![Flavio\_Campana](https://avatars.discourse-cdn.com/v4/letter/f/94ad74/32.png) [@Flavio\_Campana](https://community.gatling.io/u/Flavio_Campana)\
**Post date:** [December 13, 2018, 9:47am UTC](https://community.gatling.io/t/gatling-3-0-1-ssl-problems-even-with-useinsecuretrustmanager/4690/4 "2018-12-13T09:47:25Z")

</div>

Even on site like [www.msn.com](http://www.msn.com) i get that error, can it be something JVM related?  
The first error is now gone with jdk11 but the second one remains
