Symptom
- Configuring SNC for Kerberos using SAP Single Sign-On 3.0 or SNC Client Encryption 2.0.
- Logging on to SAP GUI results in the following error:
GSS-API(maj): Miscellaneous failure
GSS-API(min): A2200210:Peer certificate verification failed
target="SNC Name" - The Secure Login Client or SNC Client Encryption traces may show:
"Getting kerberos ticket for 'SAP/<SNC Name>' failed."
"The security database on the server does not have a computer account for this workstation trust relationship" - April 14 2026 - Microsoft have released a windows client patch that disables RC4 algorithm usage to encrypt Kerberos tokens.
This can cause failed authentication for these users if the ABAP system is not prepared for this change. In client machines
which have not yet been patched the authentication will still succeed. More details on the patch can be found here . - To prepare for this alternative AES algorithms should be configured in transaction SPNEGO
*See Resolution section for more details on identifying this as the root cause and note 3102273 - SNC Error Code A2210217 - The verification of the Kerberos ticket failed
Read more...
Environment
- SAP Single Sign-On 3.0
- SNC Client Encryption 2.0
Product
SAP Single Sign-On 3.0
Keywords
Secure Network Communication, Keytab, AD, Active Directory, Trust, X.509, A2200210, Kerberos, Ticket, SAP/, SNC Name, Failed, Security Database, Server, Computer Account, Workstation, Trust Relationship, GSS-API, Miscellaneous Failure, Peer Certificate Verification, Service Principal Name , KBA , BC-IAM-SSO-SL , Secure Login , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview