Symptom
When trying to access the system via the SAP Web Dispatcher the following warning appears:
In Web Dispatcher trace following entries can be found related to the issue:
SSL_get_state()==0x1180 "TLS read client certificate A"
*** ERROR in secussl_read: SSL_read() lasterr 0x20001046
=> "received a fatal TLS certificate unknown alert message from the peer"
srv SSL session PSE "/usr/sap/<SID>/<instance name>/sec/SAPSSLS.pse" (load=<date>, rcnt=1)
Subject : CN=<subject information>
Issuer : CN=<issuer information>
SerialNo: <serial number>
Validity - NotBefore: <Certificate validity>
NotAfter: <Certificate validity>
SSL_CTX ciphersuites=135:PFS:HIGH::EC_X25519:EC_P256:EC_HIGH
Server SSL_CTX 7f973c0971a0 pvflags=897 (TLSv1.2,TLSv1.1,TLSv1.0,BC)
TLSextSNI server_name="<hostname>"
(789_REL patchno 226,linuxx86_64_gcc43) CommonCryptoLib 8.5.53 (/usr/sap/<SID>/SYS/exe/uc/linuxx86_64/libsapcrypto.so)
secussl_read: SSL_read() failed (536875078/0x20001046)
=> "received a fatal TLS certificate unknown alert message from the peer"
SSL NI-hdl 71: local=<local IP::<port> peer=<client IP>:<port>
<<- ERROR: SapSSLSessionStartNB(sssl_hdl=7f9730000b60)==SSSLERR_ALERT_CERTIFICATE_UNKNOWN
*** ERROR => IcmConnInitServerSSL: SapSSLSessionStartNB returned (-127): SSSLERR_ALERT_CERTIFICATE_UNKNOWN [icxxconn.c 3090]
Read more...
Environment
SAP Web Dispatcher
Keywords
ERR_CERT_COMMON_NAME_INVALID, insecure, SSSLERR_ALERT_CERTIFICATE_UNKNOWN, ERROR in secussl_read, SAPSSLS.pse, host mismatch, received a fatal TLS certificate unknown alert message from the peer, Your connection is not private, SSSLERR_SSL_READ , KBA , BC-CST-WDP , Web Dispatcher , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview