SAP Knowledge Base Article - Public

3119842 - Leaf Certificate Renewal(*.c4c.saphybriscloud.cn)

Symptom

Background

The existing server certificate (Leaf Certificate) for domain “*.c4c.saphybriscloud.cn” is being renewed as it will get expired on June 03rd 2025.

Please note that the certificate chains (root and Intermediate certificates) are also getting changed along with the leaf certificate, so entire chain must be installed in your Integrations, wherever it is used to work.

Also, there is a change in the signature algorithm of the certificate where it is moving from sha256RSA to sha384ECDSA (Elliptic Curve Digital Signature Algorithm) in-order to meet the security requirements – so if in-case you are using any older version tools or browsers it may not be supported, hence please upgrade your tools to the supported version.

Timelines

Change will be executed on May 09th2025 between 18:00 and 22:00 UTC for Test Systems.

Change will be executed on May 24th2025 between 15:00 and 19:00 UTC for Production Systems.

Environment

 SAP Cloud for Customer

Resolution

ACTION REQUIRED

If you have third party integrations like web services/APIs in your test/production environment, you may be required to add the new certificate chain in the required trust stores.

PLEASE NOTE: Issuer certificates (Root and Intermediate) of *.c4c.saphybriscloud.cn are getting changed. So please update their chains as well in your integrations.

FAQ's

  • What is the being done at our side with regards to the renewal?

Answer: We shall replace the new PSE (renewed PSE) at our side which is being issued by the Root and Intermediate Certificates.

  • What does this renewal mean to you while accessing C4C tenants from browser?

Answer: No action required, you can access your C4C systems through browser normally after the certificate renewal.

  • What does this renewal mean when you are using systems for integration with C4C systems?

Answer: In case if you have uploaded the leaf certificate as well (*.c4c.saphybriscloud.cn) in your local system or integration system, you may update this with the new leaf certificate, you can download the new leaf certificate from the section mentioned above: "Download New Certificate"

NOTE: In general, for SSL handshake between C4C system and your system having ROOT and Intermediate certificate of leaf certificate should suffice (i.e.: DigiCert Global Root G3 and DigiCert Global G3 TLS ECC SHA384 2020 CA1). 

  • How to check the certificate in my browser trust list


Google Chrome : Open settings in chrome browser and search for security in the search box and click on it. 

''

Go to manage certificates tab and click on it to see the certificates window popup 

''

And check in “Trusted root certification Authorities” list and you should find “DigiCert Global Root G3". 

Picture 1, Picture

  • Similarly check in “Intermediate Certification Authorities” list and you should find “DigiCert Global G3 TLS ECC SHA384 2020 CA1". 

Picture 1, Picture



Microsoft Edge:

  1. Open Microsoft Edge.

  1. Open settings in Microsoft Edge and search for security in the search box and click on it.

  1. Click on Manage Certificates

''


And check in “Trusted root certification Authorities” list and you should find “DigiCert Global Root G3".

Picture 1, Picture


Similarly check in “Intermediate Certification Authorities” list and you should find “DigiCert Global G3 TLS ECC SHA384 2020 CA1".

Picture 1, Picture

If the certificate is not present, please proceed with steps mentioned under: “How to import certificate into my browser?”

How to import the certificate into my browser? 
  1. Open Google Chrome or Microsoft Edge.
  2. Open settings and search for security in the search box and click on it.
  3. Click on Manage Device Certificates / Manage Certificates.
  4. Go to tab “Trusted root certification Authorities” list and Import attached Digi Certificates using "Import" button at bottom.
  5. Go to tab “Intermediate certification Authorities” list and Import attached Digi Certificates using "Import" button at bottom.
Ensure that “DigiCert Root and Intermediate" is added in the list. 
  • I notice a discrepancy in the validity start date and end date mentioned in this knowledge article table and my downloaded certificate. What does this indicate?


Answer : Sometimes, due to time zone difference, you may see a different date in the downloaded certificate. There is no impact on the certificate update activity due to this. You will be renewing the certificate well in advance, before the certificate expiry date.

Keywords

KBA , LOD-CRM-SEC , Security Topics , How To

Product

SAP Cloud for Customer core applications all versions

Attachments

star_c4c_saphybriscloud_cn_ecc_2025.zip