Loading

CloudHub 2.0 Private Space TLS Context Upload Fails with "Invalid CA Path file uploaded. Certificate Chain validation failed"

Fecha de publicación: Jul 29, 2026
Descripción
ISSUE:
When uploading a client certificate (CA-signed or self-signed) to a Private Space TLS context truststore, the upload is rejected with the error:
"Invalid CA Path file uploaded. Certificate Chain validation failed."
This can occur even when the certificate chain is correctly formatted, PEM-encoded, and includes all required intermediate CA certificates in the correct order.

CAUSE:
This matches an Engineering-acknowledged Known Issue affecting CloudHub 2.0 Private Space TLS contexts (see reference below). At the time of writing, no permanent fix has shipped and the Known Issue page does not publish a workaround.



Solución
The following workaround has resolved this exact error across multiple support cases:
- Open the affected TLS context and select Edit. Do NOT delete and recreate the TLS context.
- In the edit window, re-enter ALL configuration values, even fields that have not changed: server certificate, private key, CA path, and the Truststore.
- Select Update TLS Context to apply the changes.
Re-entering the complete set of values during an in-place edit is the key step. This allows certificate chain validation to complete successfully where a partial edit does not.

If the error persists after trying this workaround, confirm the following about the uploaded file:
- It is PEM encoded (begins with -----BEGIN CERTIFICATE----- and ends with -----END CERTIFICATE-----).
- It includes any intermediate CA certificate(s) needed to complete the chain.
- The certificates are concatenated in order: intermediate CA(s) first, then the root CA.

Recursos adicionales

ADDITIONAL NOTES:
This is a workaround, not a permanent fix. Check the Known Issue page periodically for a status update, as the underlying platform behavior is still being tracked by the CloudHub 2.0 Private Spaces engineering team.

REFERENCES: Known Issue: https://help.salesforce.com/s/issue?id=a02Ka00000eNx4xIAC Configuring Endpoints and Paths for Apps Deployed to a Private Space: https://docs.mulesoft.com/cloudhub-2/ch2-deploy-private-space#configure-endpoint-path
Número del artículo de conocimiento

005390239

 
Cargando
Salesforce Help | Article