Next Practical Step
Identify whether the failure is HTTP sampler TLS, recorder CA, or distributed RMI SSL, then apply the matching section above.
Fix JMeter SSLHandshakeException and PKIX path building failed: truststore, SNI, TLS version, client certs, and recorder CA issues. Symptom, causes, fixes.
Samples fail with TLS-related messages, often wrapped as Non HTTP response errors:
javax.net.ssl.SSLHandshakeExceptionPKIX path building failed / unable to find valid certification pathReceived fatal alert: handshake_failurejavax.net.ssl.SSLException: Unsupported or unrecognized SSL message (TLS aimed at a port that answers with plain HTTP)unknown_ca or HTTPS pages never record cleanly (recorder best practices)HTTP may work in a browser that already trusts the corporate CA, while JMeterโs JVM does not.
| Cause | Notes |
|---|---|
| Untrusted server certificate | Lab/self-signed or private PKI not in the JVM truststore JMeter uses |
| Hostname / SNI mismatch | Certificate CN/SAN does not match the server name in the sampler |
| TLS version or cipher mismatch | Server requires TLS 1.2+; client restricted by JVM or properties |
| TLS aimed at a plain HTTP port | Unsupported or unrecognized SSL message; the serverโs plain HTTP reply cannot be parsed as a TLS handshake |
| Client certificate required | Mutual TLS; keystore not configured on the HTTP Request / system properties |
| Recorder without JMeter CA | HTTPS recording needs ApacheJMeterTemporaryRootCA trusted (proxy tutorial) |
| RMI SSL between engines | Distributed mode since JMeter 4.0 defaults to SSL for RMI (remote testing) - different from HTTP TLS |
https and the correct port (usually 443).This variant is a protocol/port mismatch, not a certificate problem:
https against a port that serves plain HTTP triggers this error, because the server answers with HTTP text the TLS layer cannot parse.curl -v http://host:port/ versus curl -vk https://host:port/.http for plain HTTP ports, https for TLS ports (usually 443).https; the backend ports behind it are usually plain HTTP and reject TLS.ApacheJMeterTemporaryRootCA.crt from the JMeter launch directory into the browser trust store.proxyserver.jks when documented).unknown_ca usually means the browser has not accepted the JMeter proxy certificate.create-rmi-keystore scripts and distribute rmi_keystore.jks to controller and workers.SSLHandshakeException against the SUT - check whether the error is on jmeter-server startup or on an HTTP sampler.| Resource | Use when |
|---|---|
| HTTP recorder | Recording HTTPS |
| Properties cheat sheet | SSL-related properties |
| Remote testing | RMI SSL keystores |
| Non HTTP response code | How JMeter wraps SSL errors |
Browsers use the OS trust store. JMeter uses the JVM trust store unless configured otherwise. Corporate CAs often exist in one but not the other.
Related family: unknown_ca during recording means the browser rejected the JMeter MITM CA. Load-test SSLHandshakeException usually means JMeter rejected the server certificate (or mTLS failed).
Only in controlled non-production labs, and document it. Production-like tests should use proper trust material so TLS cost and failures are realistic.
It means JMeter tried to speak TLS to a port that answers with something else, usually plain HTTP. The serverโs reply cannot be parsed as a TLS handshake. Check the samplerโs protocol and port, and use https only against ports that actually serve TLS.