Symptom
Scenario 1:
After configuring SSL, to start the SAP Web Dispatcher or the Message Server of the ASCSxx/SCSxx instance.
However, it fails to start service in HTTPS port. The following error is observed in the trace ("dev_webdisp" for the SAP Web Dispatcher; "dev_ms" for the Message Server):
[Thr 6992] *** ERROR => secussl_Create_SSL_CTX(): PSE "<server PSE file>": unable to use! [ssslsecu.c 2399]
[Thr 6992] secussl_Create_SSL_CTX: SSL_CTX_set_default_pse_by_name() failed (1824/0x00000720)
[Thr 6992] => "Wrong or missing PIN for PSE."
[Thr 6992] >> ---------- Begin of Secu-SSL Errorstack ---------- >>
[Thr 6992] 0x00000720 | SAPCRYPTOLIB | SSL_CTX_set_default_pse_by_name
[Thr 6992] SAPCRYPTO API error
[Thr 6992] Wrong or missing PIN for PSE.
[Thr 6992] 0xa1d5012c | TOKEN_TOKPSE | sec_SSL_CTX_set_asc
[Thr 6992] Wrong PIN
[Thr 6992] << ---------- End of Secu-SSL Errorstack ----------
[Thr 6992] *** ERROR => SapISSLAddCredential(): Error SSSLERR_PSE_ERROR trying to create SERVER Credential
for "<server PSE file>" [ssslxxi.c 2805]
[Thr 6992] *** ERROR => Initialization of SSL library failed -- NO SSL available!
[Thr 6992] =================================================
[Thr 6992]
[Thr 6992] <<- ERROR: SapSSLInit(read_profile=1)==SSSLERR_PSE_ERROR
[Thr 6992] *** ERROR => IcmServInitSSL: SapSSLInit (rc=-40): SSSLERR_PSE_ERROR [icxxserv.c 497]
[Thr 6992] *** WARNING => IcmAddService: Could not start service (rc=-14)
Scenario 2:
After configuring a CA-signed certificate in STRUST for an ASCS instance and restarting sapstartsrv, the service continues to present the self-signed SystemPKI certificate on the HTTPS port (e.g., 50314)
The sapstartsrv trace confirms: Webservice SSL thread using system PKI credential:
Webservice named pipe thread started, listening on port \\.\pipe\sapcontrol_03
Webservice SSL thread started, listening on port 50314
Webservice SSL thread using system PKI credential
To see more detail, you need to increase the sapstartsrv log to level 3. Follow 2451419 - How to get level 3 trace of SAP Host Agent
The following errors appear:
[Thr 9760] *** ERROR => secussl_Create_SSL_CTX(): PSE "<Server PSE file>": missing SSO credentials, PSE is protected with PIN/password! [ssslsecu.c 3922]
[Thr 9760] secussl_Create_SSL_CTX: SSL_CTX_set_default_pse_by_name() failed (1824/0x00000720)
[Thr 9760] => "Wrong or missing PIN for PSE."
[Thr 9760] >> ===== SecuSSL ErrStack: =====
[Thr 9760] 0x00000720 | SAPCRYPTOLIB | SSL_CTX_set_default_pse_by_name
[Thr 9760] SAPCRYPTO API error
[Thr 9760] Wrong or missing PIN for PSE.
[Thr 9760] 0xa1d5012c | TOKEN_TOKPSE | SSL_CTX_set_default_pse_by_name
[Thr 9760] Wrong PIN
[Thr 9760] Cannot open PSE (PSE=<Server PSE file>, SECUDIR=<path>\sec, user=xxx)
[Thr 9760] 0xa1d5012c | TOKEN_TOKPSE | sec_SSL_CTX_set_asc
[Thr 9760] Wrong PIN
[Thr 9760] << =============================
[Thr 9760] SapISSLDeleteCTX(): deleting SSL_CTX (cred "<NULL>",refcount=0)
[Thr 9760] *** ERROR => SapISSLAddCredential(): Error SSSLERR_PSE_MISSING_PIN trying to create SERVER Credential
for "<Server PSE file>" [ssslxxi.c 4781]
[Thr 9760] = SapISSLFlushClientCache(): Clearing out all SSL client cache sessions.
[Thr 9760]
[Thr 9760] = SapISSLFlushClientCache(): 0 session(s) cleared from SSL client cache.
[Thr 9760] DlUnloadLib: successful FreeLibrary("<folder path>\exe\sapcrypto.dll") hdl 1
[Thr 9760] *** ERROR => Initialization of SSL library failed -- NO SSL available!
Read more...
Environment
- Client/Server Technology - SAP Web Dispatcher (WDP)
- Client/Server Technology - Message Server
- SAP NetWeaver based product
- ABAP Platform based product
- SAP NetWeaver AS ABAP 7.51 or higher
- ASCS instance
- CommonCryptoLib 8
- Windows or Unix/Linux
- Database independent
Product
Keywords
SAPWebDispatcher, Webdispatcher, HTTPS, secure, failover, checkconfig, wdisp, dev_webdisp, webdisp, Wrong PIN for PSE, Cannot open PSE, Problems with use of system PKI, SAPSSLS.pse, SystemPKI , SSSLERR_PSE_MISSING_PIN(-82) , KBA , BC-CST-WDP , Web Dispatcher , BC-CST , Client/Server Technology , BC-SEC-SSL , Secure Sockets Layer Protocol , BC-CST-STS , Startup Service , How To
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview