SAP Knowledge Base Article - Public

3247849 - Learning IPS - mTLS Certificate Expiration [2024-2025]

Symptom

IPS tenants have an expiring mTLS certificate on August 7th, 2025. If the certificate is not updated the following issues will occur:

  • Real Time User Sync will not work correctly
  • Creation of Learning Sites will not be possible

Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental. 

Environment

  • SAP SuccessFactors Learning
  • SAP Cloud Identity Services

Resolution

NEO IPS tenants:

  1. Download the certificate in the attachments of this KBA, you may need to rename it to include the .crt extension before importing.
  2. A new cert (cer.zip in the attachments of this KBA) will be implemented in Preview on July 29th and in Production on July 31st, please download and import this cert after the dates specified.
  3. This should be the last year we have to provide customers this cert.
  4. Only customers with NEO IPS tenants will have to update the cert (unlike last year where we had an issue with the tech user causing all customers to have to upload the new cert). This should be a very small number at this point.
  5. In the Identity Provisioning admin console, select the LMS source system.

  6. Select the Inbound Certificates tab, choose Import, and select the new certificate. More info on managing certificates here.
  7. Proceed to your IAS system
  8. Access the admin record associated to your LMS integration, which would have a name/ID such as “SAP LMS – LMSTenantID”
  9. Choose certificate and import it

Note make sure the admin or technical user has the permissions toggled on, see KBA 3248892 

Converged IPS tenants:

  1. Import the new mTLS certificate into IPS tenant following the steps below: 
  2. Download the certificate from the attachments of this KBA.
  3. Proceed to your IAS system admin side >
  4. Go to "Users & Authorization" > Administrators >
  5. Access the admin record associated to your LMS integration, which would have a name/ID such as “SAP LMS – LMSTenantID” >
  6. On "Configure System Authentication" section click on "Certificate" >
  7. Click on "Browse" and select the certificate file >
  8. Perform the import process and hit "Save" icon.

Note make sure the admin or technical user has the permissions toggled on, see KBA 3248892 

See Also

3248892 - "A new Learning-only user could not be created" - Learning IAS Real Time User Sync

Keywords

IAS, IPS, cert, certificate, expired, expiration, user, creation, sync, real, time, update, read, job, , KBA , LOD-SF-LMS-IAS , LMS IAS Integration for External User , How To

Product

SAP SuccessFactors Learning all versions

Attachments

Pasted image.png
Pasted image.png
cer.zip