# SSL Certificate for Kafka running in Confluent Cloud

**URL:** <https://forum.confluent.io/t/ssl-certificate-for-kafka-running-in-confluent-cloud/9498>\
**Category:** Confluent Cloud\
**Created:** [14 December 2023 02:12 UTC](https://forum.confluent.io/t/ssl-certificate-for-kafka-running-in-confluent-cloud/9498 "2023-12-14T02:12:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![eerus](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/eerus/32/3425_2.png) [@eerus](https://forum.confluent.io/u/eerus)\
**Post date:** [14 December 2023 02:12 UTC](https://forum.confluent.io/t/ssl-certificate-for-kafka-running-in-confluent-cloud/9498/1 "2023-12-14T02:12:03Z")

</div>

Hi!  
I’m connecting to Kafka Broker in the Confluent Cloud ([https://confluent.cloud/](https://confluent.cloud/)). I’m getting this error when I try to read a Kafka topic from my Flink job  
javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

This problem might be solved if I register Kafka Broker certificate as trusted on my laptop. But how can I do it if I use Kafka through Confluent Cloud and I don’t see any option to download the certificate?

---

<div class="post-metadata">

**Author:** ![mmuehlbeyer](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.confluent.io/mmuehlbeyer/32/1088_2.png) [@mmuehlbeyer](https://forum.confluent.io/u/mmuehlbeyer)\
**Post date:** [14 December 2023 16:05 UTC](https://forum.confluent.io/t/ssl-certificate-for-kafka-running-in-confluent-cloud/9498/2 "2023-12-14T16:05:22Z")

</div>

Hi,

have a look at

> **[Connect clients and applications to Confluent Cloud | Confluent Documentation](https://docs.confluent.io/cloud/current/cp-component/clients-cloud-config.html#connect-self-managed-ak-clients-to-ccloud)**
>
> Learn how to connect your clients and applications to Confluent Cloud resources from .NET, Go, and Python applications.

Confluent Cloud is using the ISRG Root X1 Root CA, this CA is required to be part of your trust store

hth,  
michael
