SAP Knowledge Base Article - Preview

2813565 - Peer certificate rejected by ChainVerifier - Certificate name mismatch

Symptom

  • An SSL/TLS connection to an external server from the AS Java fails with "Peer certificate rejected by ChainVerifier".
  • An SSL trace with IAIK debug records (see SAP KBA 2673775) shows the following messages:

ssl_debug(7): Starting handshake (iSaSiLk 5.106)...
ssl_debug(7): Sending v3 client_hello message to <hostname>:<port>, requesting version 3.3...
ssl_debug(7): Sending extensions: renegotiation_info (...), signature_algorithms (..)
ssl_debug(7): Received v3 server_hello handshake message.
...
ssl_debug(7): Received certificate handshake message with server certificate.
...
Subject: CN=<other-hostname>...
...
name mismatch: <hostname> != <other-hostname>
...
ssl_debug(7): Sending alert: Alert Fatal: bad certificate
ssl_debug(7): SSLException while handshaking: Peer certificate rejected by ChainVerifier


Read more...

Environment

SAP NetWeaver Application Server Java

Product

SAP NetWeaver Application Server for Java all versions

Keywords

KBA , BC-JAS-SEC-CPG , Cryptography , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.