
JCrawford503169 (Community Member) asked a question.
Hello,
I'm facing a frustrating issue. Using the API Wrapper docker container as part of a CI pipeline, roughly 50% of attempts at submitting a policy scan fail with a certificate error. There's no SSL inspection device involved, and testing with tools like curl and openssl s_client shows a successful connection. I even checked that the correct root CA is present in the container image's Java trust store and it is.
The only thing I've been able to figure out is that it seems to be related to which Cloudflare edge IP api.veracode.com resolves to. I'm seeing two different addresses, and one consistently works while the other consistently results in "PKIX path building failed ... unable to find valid certification path to requested target." Yet, openssl s_client shows both IPs returning identical certificates (for SNI of api.veracode.com).
Perhaps more verbose output from the API wrapper would help diagnose the problem but I haven't found a way to get that.
.png)
Hello Crawford,
I would recommend you contact our technical support team. Here's how you can log a case:
1. Navigate to the upper right corner of any page in the Community, and click on your user avatar.
2. Select Contact Support from the drop-down menu.Open a case with Support, for Static Analysis and provide the steps you are taking to receive that error to better help assist the engineer.Regards,
Veracode Inc.With this issue, I would recommend opening a support ticket. You can open a support ticket within the Community. Simply click on your profile on the top right side of the screen and select "Contact Support". Or click on the link below.https://community.veracode.com/s/contact-support
Regards,
Sanjay
Veracode Support