I have a large number (~100) of build agents connecting to a server which I have recently configured with SSL. For almost all of them adding the servers certificate in teamcity/conf/trustedCertificates is good enough to validate the certificate and connect.
However, I have one machine, which is a raspberry pi running Raspian 8, it's giving me this error:
[2021-02-08 16:11:25,101] WARN - buildServer.AGENT.registration - Error while asking server for the communication protocols via URL https://teamcity.apama.com/app/agents/protocols. Will try later: javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target (enable debug to see stacktrace)
[2021-02-08 16:11:25,102] WARN - buildServer.AGENT.registration - Error registering on the server via URL https://teamcity.apama.com. Will continue repeating connection attempts.
The conf directory is stored in SVN and it's both up to date on this machine, and identical to one of the other 8 identically configured Raspberry PIs also running teamcity agents which are connecting just fine.
I also followed the other suggestions from related threads and attempted to configure the standard Java trust store with the root cert signing this server's certificate and with specifying the location and password to the cacerts trust store in buildAgent.properties. All to no avail.
I've tried enabling DEBUG-level logging, but the stack trace doesn't contain any more interesting messages than the one produced at WARN.
Please let me know if you have any other suggestions, this is a PRODUCTION DOWN issue.