<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Environment Active Gate - AWS monitoring Failed to load configured trustedstore file, aborting custom certificate configuratio in Cloud platforms</title>
    <link>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256532#M1762</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Update : Cert Issue was Solved:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/21657"&gt;@p_devulapalli&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/51369"&gt;@Peter_Youssef&lt;/a&gt;&amp;nbsp; :&lt;/P&gt;&lt;P&gt;The cert issue was finally resolved by having the&amp;nbsp;&lt;SPAN&gt;proxy specifically for Dynatrace Cluster, while allowing outgoing monitoring traffic to connect directly to AWS . Update done for &lt;STRONG&gt;custom.properties&lt;/STRONG&gt; by defining proxy settings in the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;[http.client.internal]&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;section ( instead of&lt;EM&gt; [http.client]&lt;/EM&gt; )&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 20 Sep 2024 02:12:53 GMT</pubDate>
    <dc:creator>dyn98007</dc:creator>
    <dc:date>2024-09-20T02:12:53Z</dc:date>
    <item>
      <title>Environment Active Gate - AWS monitoring Failed to load configured trustedstore file, aborting custom certificate configuration</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256420#M1754</link>
      <description>&lt;P&gt;Related to the AWS account connectivity error ….. &lt;EM&gt;com.amazonaws.SdkClientException: Unable to execute HTTP request: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’m facing an issue where the&amp;nbsp; trustedstore file is not getting loaded correctly from the path - &lt;EM&gt;/var/lib/dynatrace/gateway/ssl/trusted.p12.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;This is resulting in a&lt;STRONG&gt; java.io.FileNotFoundException&lt;/STRONG&gt;. Details below&lt;/P&gt;&lt;P&gt;The trustedstore file &amp;nbsp;file has mentioned in the&lt;EM&gt; custom.properties&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[collector]&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;trustedstore = trusted.p12&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;trustedstore-password = changeit&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;trustedstore-type = PKCS12&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The error mentioned in &lt;EM&gt;dynatracegateway_Debug.0.0.log&lt;/EM&gt; file captured below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2024-09-19 00:07:00 UTC INFO&amp;nbsp;&amp;nbsp;&amp;nbsp; [&amp;lt;header&amp;gt;] +-----------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;2024-09-19 00:07:00 UTC INFO&amp;nbsp;&amp;nbsp;&amp;nbsp; [&amp;lt;header&amp;gt;] + Version 1.295.7.20240715-224910&lt;/P&gt;&lt;P&gt;2024-09-19 00:07:00 UTC INFO&amp;nbsp;&amp;nbsp;&amp;nbsp; [&amp;lt;header&amp;gt;] + collector: 0x7cd018cb; tenant: fefc24a4-d245-44cb-9623-f73b0e7e190c;&lt;/P&gt;&lt;P&gt;2024-09-19 00:07:00 UTC INFO&amp;nbsp;&amp;nbsp;&amp;nbsp; [&amp;lt;collector&amp;gt;] [&amp;lt;com.compuware.apm.logging&amp;gt;, LoggingServiceImpl] Platform: Linux, Version: 5.14.0-284.82.1.el9_2.x86_64, Architecture: amd64, Processors: 4&lt;/P&gt;&lt;P&gt;2024-09-19 00:07:00 UTC INFO&amp;nbsp;&amp;nbsp;&amp;nbsp; [&amp;lt;collector&amp;gt;] [&amp;lt;com.compuware.apm.logging&amp;gt;, LoggingServiceImpl] VM: OpenJDK 64-Bit Server VM, Version: 17.0.10, Vendor: Eclipse Adoptium, Memory [maxMemory=10280M, initHeap=1024M, maxHeap=10280M, usedMeta=7M, committedMeta=7M, totalPhysicalMemory=15809M, freePhysicalMemory=10068M]&lt;/P&gt;&lt;P&gt;2024-09-19 00:07:00 UTC INFO&amp;nbsp;&amp;nbsp;&amp;nbsp; [&amp;lt;collector&amp;gt;] [&amp;lt;com.compuware.apm.logging&amp;gt;, LoggingServiceImpl] file.encoding: UTF-8, sun.jnu.encoding: UTF-8, user.name: dtuserag&lt;/P&gt;&lt;P&gt;2024-09-19 00:07:00 UTC INFO&amp;nbsp;&amp;nbsp;&amp;nbsp; [&amp;lt;collector&amp;gt;] [&amp;lt;com.compuware.apm.logging&amp;gt;, LoggingServiceImpl] Input Arguments: -Dcom.compuware.apm.WatchDogTimeout=180 --add-opens=java.base/java.lang=ALL-UNNAMED -Xms1024M -XX:ErrorFile=/var/log/dynatrace/gateway/hs_err_pid_%p.log -XX:+UseG1GC -XX:+IgnoreUnrecognizedVMOptions -Duser.language=en -Djava.util.logging.manager=com.dynatrace.gen2.foundation.logging.impl.backend.CustomShutdownLogManager -Djdk.tls.ephemeralDHKeySize=2048 -Dorg.xerial.snappy.lib.path=/opt/dynatrace/gateway/lib/native -Dorg.xerial.snappy.lib.name=libsnappyjava.so -Djava.io.tmpdir=/var/lib/dynatrace/gateway/temp -Dfile.encoding=UTF-8 -Dsun.jnu.encoding=UTF-8 -Djava.security.egd=file:/dev/urandom -DZstdNativePath=/opt/dynatrace/gateway/lib/native/libzstd-jni.so -Xmx10275M -Dcom.compuware.apm.WatchDogPort=50000&lt;/P&gt;&lt;P&gt;2024-09-19 00:07:00 UTC INFO&amp;nbsp;&amp;nbsp;&amp;nbsp; [&amp;lt;collector&amp;gt;] [&amp;lt;collector.core&amp;gt;, CollectorImpl] No keyfile detected, starting without crypto subsystem.&lt;/P&gt;&lt;P&gt;2024-09-19 00:07:00 UTC INFO&amp;nbsp;&amp;nbsp;&amp;nbsp; [&amp;lt;collector&amp;gt;] [&amp;lt;collector.comm&amp;gt;, TrustStoreCreator] Setting up combined trust store, Java cacerts: TrustStoreSettingsImpl{path=/opt/dynatrace/gateway/jre/lib/security/cacerts, type=pkcs12}, custom: TrustStoreSettingsImpl{path=/var/lib/dynatrace/gateway/config/../ssl/concurtrusted.p12, type=PKCS12}&lt;/P&gt;&lt;P&gt;2024-09-19 00:07:00 UTC WARNING [&amp;lt;collector&amp;gt;] [&amp;lt;collector.comm&amp;gt;, TrustStoreCreator] &lt;STRONG&gt;&lt;EM&gt;Failed to load configured trustedstore file (full path: /var/lib/dynatrace/gateway/config/../ssl/trusted.p12), aborting custom certificate configuration&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;java.io.FileNotFoundException: /var/lib/dynatrace/gateway/config/../ssl/concurtrusted.p12 (Permission denied)&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at java.base/java.io.FileInputStream.open0(Native Method)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at java.base/java.io.FileInputStream.open(Unknown Source)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at java.base/java.io.FileInputStream.&amp;lt;init&amp;gt;(Unknown Source)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at java.base/java.io.FileInputStream.&amp;lt;init&amp;gt;(Unknown Source)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at com.dynatrace.apm.collector.shared.communication.api.truststore.TrustStoreCreator.createKeyStoreFromTrustStore(TrustStoreCreator.java:146)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at com.dynatrace.apm.collector.shared.communication.api.truststore.TrustStoreCreator.handleCustomTS(TrustStoreCreator.java:96)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at com.dynatrace.apm.collector.shared.communication.api.truststore.TrustStoreCreator.setupCerts(TrustStoreCreator.java:66)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at com.compuware.apm.collector.core.CollectorImpl.setupTrustStore(CollectorImpl.java:346)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at com.compuware.apm.collector.core.CollectorImpl.&amp;lt;init&amp;gt;(CollectorImpl.java:314)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at com.compuware.apm.collector.core.CollectorImpl.main(CollectorImpl.java:803)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2024-09-19 00:07:01 UTC INFO&amp;nbsp;&amp;nbsp;&amp;nbsp; [&amp;lt;collector&amp;gt;] [&amp;lt;collector.comm&amp;gt;, TrustStoreCreator] Effective trust store: TrustStoreSettingsImpl{path=/opt/dynatrace/gateway/jre/lib/security/cacerts, type=pkcs12}&lt;/P&gt;&lt;P&gt;----------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Due to the failure to load the configured trustedstore file..below error message show up in the &lt;STRONG&gt;dynatracegateway_Debug.0.0.log..&amp;nbsp; T&lt;/STRONG&gt;he error comes up when an attempt is made to connect to an AWS account in the Dynatrace UI. Screenshot attached.&lt;/P&gt;&lt;P&gt;Please advise&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Error :&amp;nbsp;&lt;/STRONG&gt;&lt;EM&gt;Unable to execute HTTP request: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Details below:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2024-09-19 03:03:00 UTC INFO&amp;nbsp;&amp;nbsp;&amp;nbsp; [&amp;lt;d245-44cb-9623-f73b0e7e190c &amp;gt;] [&amp;lt;vtopology.provider&amp;gt;, AWSClientFactory] trying to get client initial response for credentials: AWSCredentialsImpl {identifier: BEEB1840447456B1, accessKey: null, secretKey: null, tenantUUID: -d245-44cb-9623-f73b0e7e190c, iamRole: Dynatrace_monitoring_role, accountId: 1233445, externalId: *****, label: Integration Observe RoleBased, partition: aws, detectedPartition: null, monitorOnlyTaggedEntities: false, includeTags: [], excludeTags: [], excludedRegions: [], logConfigSQSesEnabled: false, logConfigSQSes: [], version: 2.0, legacyServices: [ebs_builtin, lambda_builtin, ELB_builtin, loadbalancer_builtin, s3_builtin, dynamodb_builtin, ec2_builtin, asg_builtin, rds_builtin], services: [], extensionDetails: null} [Suppressing further messages for 15 minutes] [skipped logs: 1]&lt;/P&gt;&lt;P&gt;2024-09-19 03:03:00 UTC DEBUG&amp;nbsp;&amp;nbsp; [&amp;lt;d245-44cb-9623-f73b0e7e190c &amp;gt;] [&amp;lt;vtopology.provider&amp;gt;, PartitionAutoDetection] detectedPartition=aws, for credentials: Integration Observe RoleBased [7025090340361789595]&lt;/P&gt;&lt;P&gt;2024-09-19 03:03:01 UTC INFO&amp;nbsp;&amp;nbsp;&amp;nbsp; [] [, RoleCredentialsProvider] Cannot obtain CLIENT short term credentials for arn&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.dynatrace.com/html/@F9676CCDE08B8746467ACFFDC4C9827E/images/emoticons/aws.png" alt=":aws:" title=":aws:" /&gt;iam::420785284875:role/Dynatrace_monitoring_role ; AWSCredentialsImpl {identifier: BEEB1840447456B1, accessKey: null, secretKey: null, tenantUUID: d245-44cb-9623-f73b0e7e190c iamRole: Dynatrace_monitoring_role, accountId: 420785284875, externalId: *****, label: Integration Observe RoleBased, partition: aws, detectedPartition: aws, monitorOnlyTaggedEntities: false, includeTags: [], excludeTags: [], excludedRegions: [], logConfigSQSesEnabled: false, logConfigSQSes: [], version: 2.0, legacyServices: [ebs_builtin, lambda_builtin, ELB_builtin, loadbalancer_builtin, s3_builtin, dynamodb_builtin, ec2_builtin, asg_builtin, rds_builtin], services: [], extensionDetails: null} [Suppressing further identical messages for 10 minutes]&lt;/P&gt;&lt;P&gt;com.amazonaws.SdkClientException: Unable to execute HTTP request: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; at com.amazonaws.http.AmazonHttpClient$RequestExecutor.handleRetryableException(AmazonHttpClient.java:1219)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2024-09-19 03:03:01 UTC WARNING [&amp;lt;d245-44cb-9623-f73b0e7e190c &amp;gt;] [&amp;lt;vtopology.provider&amp;gt;, AWSFastCheckCallable] Credentials refresh failed: {status: ERROR_BAD_CREDENTIALS, statusInfo: Service failed to assume role provided in credentials. An unknown error related to role has occurred, credentials: AWSCredentialsImpl {identifier: BEEB1840447456B1, accessKey: null, tenantUUID: d245-44cb-9623-f73b0e7e190c,iamRole: Dynatrace_monitoring_role, accountId: 1233445, externalId: *****, label: Integration Observe RoleBased, version: 2.0}, exception: com.amazonaws.SdkClientException:&lt;EM&gt;&lt;STRONG&gt; Unable to execute HTTP request: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 04:48:11 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256420#M1754</guid>
      <dc:creator>dyn98007</dc:creator>
      <dc:date>2024-09-19T04:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to load configured trustedstore file, aborting custom certificate configuration</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256422#M1755</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/79860"&gt;@dyn98007&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like a permission issue , does the user have permissions to the directory?&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.dynatrace.com/docs/shortlink/activegate-configuration-trusted-root-certs#check-permissions" target="_blank" rel="noopener"&gt;https://docs.dynatrace.com/docs/shortlink/activegate-configuration-trusted-root-certs#check-permissions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 04:43:40 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256422#M1755</guid>
      <dc:creator>p_devulapalli</dc:creator>
      <dc:date>2024-09-19T04:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to load configured trustedstore file, aborting custom certificate configuration</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256425#M1756</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/21657"&gt;@p_devulapalli&lt;/a&gt;&amp;nbsp; for the pointer to&amp;nbsp;check-permissions.&lt;/P&gt;&lt;P&gt;The ownership of the .p12 file was changed to the &lt;EM&gt;dtuserag&lt;/EM&gt;, and the dyntracegateway service was restarted. It&amp;nbsp;&lt;STRONG&gt;fixed&lt;/STRONG&gt; the previous error related to&amp;nbsp;&lt;EM&gt;java.io.FileNotFoundException&lt;/EM&gt;&lt;STRONG&gt; .&lt;/STRONG&gt;&lt;EM&gt;.( as seen below) ... &lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2024-09-19 04:53:15 UTC INFO [&amp;lt;collector&amp;gt;] [&amp;lt;collector.comm&amp;gt;, TrustStoreCreator] Setting up combined trust store, Java cacerts: TrustStoreSettingsImpl{path=/opt/dynatrace/gateway/jre/lib/security/cacerts, type=pkcs12}, custom: TrustStoreSettingsImpl{path=/var/lib/dynatrace/gateway/config/../ssl/trusted.p12, type=PKCS12}&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;2024-09-19 04:53:15 UTC INFO [&amp;lt;collector&amp;gt;] [&amp;lt;collector.comm&amp;gt;, TrustStoreCreator] overwriting existing certificate with alias trustedca&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;2024-09-19 04:53:15 UTC INFO [&amp;lt;collector&amp;gt;] [&amp;lt;collector.comm&amp;gt;, TrustStoreCreator] overwriting existing certificate with alias /etc/pki/ca-trust/source/anchors/root-cert-0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;2024-09-19 04:53:15 UTC INFO [&amp;lt;collector&amp;gt;] [&amp;lt;collector.comm&amp;gt;, TrustStoreCreator] overwriting existing certificate with alias /etc/pki/ca-trust/source/anchors/root-cert-1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;2024-09-19 04:53:15 UTC INFO [&amp;lt;collector&amp;gt;] [&amp;lt;collector.comm&amp;gt;, TrustStoreCreator] overwriting existing certificate with alias /etc/pki/ca-trust/source/anchors/root-cert-2&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;2024-09-19 04:53:15 UTC INFO [&amp;lt;collector&amp;gt;] [&amp;lt;collector.comm&amp;gt;, TrustStoreCreator] &lt;STRONG&gt;Custom certificate configuration created successfully&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;2024-09-19 04:53:15 UTC INFO [&amp;lt;collector&amp;gt;] [&amp;lt;collector.comm&amp;gt;, TrustStoreCreator] Effective trust store: TrustStoreSettingsImpl{path=/var/lib/dynatrace/gateway/config/../ssl/runtime.cacerts, type=pkcs12}&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;---------------------------&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;But unfortunately the "Invalid credentials" message still show up in the UI while trying to add an AWS account , and with the below captured error info in the&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;dynatracegateway_Debug.0.0.log &lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;-------------------&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2024-09-19 04:57:23 UTC WARNING [&amp;lt;f44cb-9623-f73b0e7e190c&amp;gt;] [&amp;lt;vtopology.provider&amp;gt;, AWSFastCheckCallable] Credentials refresh failed: {status: ERROR_BAD_CREDENTIALS, statusInfo: Service failed to assume role provided in credentials. An unknown error related to role has occurred, credentials: AWSCredentialsImpl {identifier: 9B5D617D1A7B8D61, accessKey: null, tenantUUID: f44cb-9623-f73b0e7e190c,iamRole: Dynatrace_monitoring_role, accountId: 484875, externalId: *****, label: Integration Observe RoleBased, version: 2.0}, exception: com.amazonaws.SdkClientException: Unable to execute HTTP request: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;2024-09-19 04:57:33 UTC DEBUG [&amp;lt;f44cb-9623-f73b0e7e190c&amp;gt;] [&amp;lt;vtopology.provider&amp;gt;, PartitionAutoDetection] detectedPartition=aws, for credentials: Integration Observe RoleBased [-4866113436641686085]&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;2024-09-19 04:57:34 UTC INFO [&lt;/EM&gt;] [&lt;EM&gt;, RoleCredentialsProvider] Cannot obtain CLIENT short term credentials for arn&lt;/EM&gt;&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.dynatrace.com/html/@F9676CCDE08B8746467ACFFDC4C9827E/images/emoticons/aws.png" alt=":aws:" title=":aws:" /&gt;&lt;EM&gt;iam::484875:role/Dynatrace_monitoring_role ; AWSCredentialsImpl {identifier: ACCC65D26456AF7B, accessKey: null, secretKey: null, tenantUUID: f44cb-9623-f73b0e7e190c, iamRole: Dynatrace_monitoring_role, accountId: 484875, externalId: *****, label: Integration Observe RoleBased, partition: aws, detectedPartition: aws, monitorOnlyTaggedEntities: false, includeTags: [], excludeTags: [], excludedRegions: [], logConfigSQSesEnabled: false, logConfigSQSes: [], version: 2.0, legacyServices: [ebs_builtin, lambda_builtin, ELB_builtin, loadbalancer_builtin, s3_builtin, dynamodb_builtin, ec2_builtin, asg_builtin, rds_builtin], services: [], extensionDetails: null} [Suppressing further identical messages for 10 minutes]&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;com.amazonaws.SdkClientException: Unable to execute HTTP request: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;at com.amazonaws.http.AmazonHttpClient$RequestExecutor.handleRetryableException(AmazonHttpClient.java:1219)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2024-09-19 04:57:34 UTC WARNING [&amp;lt;f44cb-9623-f73b0e7e190c&amp;gt;] [&amp;lt;vtopology.provider&amp;gt;, AWSFastCheckCallable] Credentials refresh failed: {status: ERROR_BAD_CREDENTIALS, statusInfo: Service failed to assume role provided in credentials. An unknown error related to role has occurred, credentials: AWSCredentialsImpl {identifier: ACCC65D26456AF7B, accessKey: null, tenantUUID: f44cb-9623-f73b0e7e190c,iamRole: Dynatrace_monitoring_role, accountId: 484875, externalId: *****, label: Integration Observe RoleBased, version: 2.0}, exception: com.amazonaws.SdkClientException: Unable to execute HTTP request: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target}&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;----------------&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 05:40:05 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256425#M1756</guid>
      <dc:creator>dyn98007</dc:creator>
      <dc:date>2024-09-19T05:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: Environment Active Gate - AWS monitoring Failed to load configured trustedstore file, aborting custom certificate configuratio</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256426#M1757</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/79860"&gt;@dyn98007&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;validate your Activegate configurations against Dynatrace guidance references:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;A href="https://docs.dynatrace.com/managed/shortlink/ag-configuration#trusted-certificates-and-custom-certificates" target="_self"&gt;trusted-certificates-and-custom-certificates&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.dynatrace.com/managed/shortlink/activegate-ciphers" target="_self"&gt;activegate-ciphers&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 05:32:52 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256426#M1757</guid>
      <dc:creator>Peter_Youssef</dc:creator>
      <dc:date>2024-09-19T05:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to load configured trustedstore file, aborting custom certificate configuration</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256427#M1758</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/79860"&gt;@dyn98007&lt;/a&gt;&amp;nbsp;- It could be a issue with the cert that you are using, please make sure its the right one&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 05:50:41 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256427#M1758</guid>
      <dc:creator>p_devulapalli</dc:creator>
      <dc:date>2024-09-19T05:50:41Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to load configured trustedstore file, aborting custom certificate configuration</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256440#M1759</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/21657"&gt;@p_devulapalli&lt;/a&gt;&amp;nbsp; - I did reconfirm that the right one is being used. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 06:57:38 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256440#M1759</guid>
      <dc:creator>dyn98007</dc:creator>
      <dc:date>2024-09-19T06:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: Environment Active Gate - AWS monitoring Failed to load configured trustedstore file, aborting custom certificate configuratio</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256532#M1762</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Update : Cert Issue was Solved:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/21657"&gt;@p_devulapalli&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/51369"&gt;@Peter_Youssef&lt;/a&gt;&amp;nbsp; :&lt;/P&gt;&lt;P&gt;The cert issue was finally resolved by having the&amp;nbsp;&lt;SPAN&gt;proxy specifically for Dynatrace Cluster, while allowing outgoing monitoring traffic to connect directly to AWS . Update done for &lt;STRONG&gt;custom.properties&lt;/STRONG&gt; by defining proxy settings in the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;[http.client.internal]&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;section ( instead of&lt;EM&gt; [http.client]&lt;/EM&gt; )&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2024 02:12:53 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256532#M1762</guid>
      <dc:creator>dyn98007</dc:creator>
      <dc:date>2024-09-20T02:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: Environment Active Gate - AWS monitoring Failed to load configured trustedstore file, aborting custom certificate configuratio</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256537#M1763</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/79860"&gt;@dyn98007&lt;/a&gt;&amp;nbsp; Good to know&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2024 02:40:52 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256537#M1763</guid>
      <dc:creator>p_devulapalli</dc:creator>
      <dc:date>2024-09-20T02:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: Environment Active Gate - AWS monitoring Failed to load configured trustedstore file, aborting custom certificate configuratio</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256543#M1764</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/79860"&gt;@dyn98007&lt;/a&gt;&amp;nbsp;for the updates&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2024 05:34:51 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Environment-Active-Gate-AWS-monitoring-Failed-to-load-configured/m-p/256543#M1764</guid>
      <dc:creator>Peter_Youssef</dc:creator>
      <dc:date>2024-09-20T05:34:51Z</dc:date>
    </item>
  </channel>
</rss>

