SAP Knowledge Base Article - Preview

3252812 - Peer certificate rejected by ChainVerifier - BadPaddingException - encrypted message and modulus lengths do not match!

Symptom

  • An SSL/TLS connection to an external server from the AS Java fails with "Peer certificate rejected by ChainVerifier".
  • An SSL trace with IAIK debug records (see SAP KBA 2673775) shows the following messages:

    [...]
    ChainVerifier: Error verifying certificate chain: java.security.SignatureException: Signature decryption error: javax.crypto.BadPaddingException: Invalid padding!
    [...]
    ChainVerifier: Error verifying certificate chain: java.security.SignatureException: Signature decryption error: javax.crypto.BadPaddingException: Invalid PKCS#1 padding: encrypted message and modulus lengths do not match!
    [...]

    Sending alert: Alert Fatal: bad certificate
    [...]
    SSLException while handshaking: Peer certificate rejected by ChainVerifier
    [...]


Read more...

Environment

SAP NetWeaver Application Server Java using SSL for outgoing connection

Product

SAP NetWeaver Application Server for Java all versions ; SAP NetWeaver all versions

Keywords

SSl trust, certificate, trusted certificate, TLS , KBA , BC-JAS-SEC-CPG , Cryptography , BC-JAS-SEC , Security, User Management , BC-JAS-SEC-UME , User Management Engine , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.